CVE-2026-28799: PJSIP: Heap use-after-free in PJSIP presence subscription termination handler
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-free vulnerability exists in PJSIP's event subscription framework (evsub.c) that is triggered during presence unsubscription (SUBSCRIBE with Expires=0). This issue has been patched in version 2.17.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28799?
CVE-2026-28799 has been classified as a high-severity vulnerability due to its potential to be exploited for arbitrary code execution.
How do I fix CVE-2026-28799?
To fix CVE-2026-28799, upgrade PJSIP to version 2.17 or later where the vulnerability has been addressed.
What systems are affected by CVE-2026-28799?
CVE-2026-28799 affects all versions of PJSIP prior to version 2.17.
What type of vulnerability is CVE-2026-28799?
CVE-2026-28799 is a heap use-after-free vulnerability in the event subscription framework of PJSIP.
How is CVE-2026-28799 exploited?
CVE-2026-28799 can be exploited during the termination of presence subscriptions within the PJSIP framework.