CVE-2026-41416
7.5
HIGH
CVSS 3.1
EPSS 0.28%
Description
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer overflow in media stream buffer size calculation when processing SDP with asymmetric ptime configuration. The overflow may result in an undersized buffer allocation, which can lead to unexpected application termination or memory corruption This vulnerability is fixed in 2.17.
How to fix CVE-2026-41416
To remediate CVE-2026-41416, upgrade the affected package to a fixed version below.
- —upgrade to 1:22.10.0+dfsg+~cs6.17.60671434-1 or later
Is CVE-2026-41416 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1:22.10.0+dfsg+~cs6.17.60671434-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |