CVE-2026-25994

EUVD-2026-6200
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with excessively long usernames.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 78.37%
Affected Products (NVD)
VendorProductVersion
pjsippjsip
𝑥
≤ 2.16
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
asterisk
bullseye
vulnerable
bullseye (security)
1:16.28.0~dfsg-0+deb11u10
fixed
forky
1:22.10.1+dfsg+~cs6.17.60671434-1
fixed
sid
1:22.10.1+dfsg+~cs6.17.60671434-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pjproject
bionic
Fixed 2.7.2~dfsg-1ubuntu0.1~esm1
released
jammy
dne
noble
dne
questing
dne
xenial
Fixed 2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1
released