CVE-2026-25994: PJSIP has a heap buffer overflow in ICE with long username
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with excessively long usernames.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25994?
The severity of CVE-2026-25994 is classified as critical due to the potential for remote code execution via a heap buffer overflow.
How do I fix CVE-2026-25994?
To fix CVE-2026-25994, update to PJSIP version 2.17 or later where the vulnerability has been addressed.
What software versions are affected by CVE-2026-25994?
CVE-2026-25994 affects PJSIP versions 2.16 and earlier.
What are the risks associated with CVE-2026-25994?
The risks associated with CVE-2026-25994 include potential exploitation leading to arbitrary code execution on affected systems.
How does CVE-2026-25994 exploit long usernames?
CVE-2026-25994 exploits the vulnerability through a heap buffer overflow when handling excessively long usernames in PJNATH ICE Sessions.