CVE-2021-41141: Missing release of locks in PJSIP
PJSIP is a free and open source multimedia communication library written in the C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In various parts of PJSIP, when error/failure occurs, it is found that the function returns without releasing the currently held locks. This could result in a system deadlock, which cause a denial of service for the users. No release has yet been made which contains the linked fix commit. All versions up to an including 2.11.1 are affected. Users may need to manually apply the patch.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this PJSIP vulnerability?
The vulnerability ID for this PJSIP vulnerability is CVE-2021-41141.
What is PJSIP?
PJSIP is a free and open source multimedia communication library written in the C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE.
What is the severity of CVE-2021-41141?
The severity of CVE-2021-41141 is high with a severity value of 7.5.
What is the affected software?
The affected software includes Teluu PJSIP up to and including version 2.11.1 and Debian Debian Linux 9.0.
How can I fix CVE-2021-41141?
To fix CVE-2021-41141, it is recommended to update to a patched version of Teluu PJSIP or upgrade to a newer version of Debian Debian Linux.