CVE-2026-29068: PJSIP: Stack buffer overflow in Opus codec parser
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack buffer overflow vulnerability when pjmedia-codec parses an RTP payload contain more frames than the caller-provided frames can hold. This issue has been patched in version 2.17.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29068?
CVE-2026-29068 is classified as a critical severity vulnerability due to the potential for remote code execution through a stack buffer overflow.
How do I fix CVE-2026-29068?
To mitigate CVE-2026-29068, upgrade PJSIP to version 2.17 or later where the vulnerability has been patched.
What versions of PJSIP are affected by CVE-2026-29068?
CVE-2026-29068 affects versions of PJSIP prior to version 2.17.
What is the nature of the vulnerability in CVE-2026-29068?
CVE-2026-29068 is a stack buffer overflow vulnerability in the Opus codec parser of the PJSIP library.
Can CVE-2026-29068 be exploited remotely?
Yes, CVE-2026-29068 can be exploited remotely through specially crafted RTP payloads.