REDHAT-BUG-2427788: Null Pointer Dereference
Published Jan 8, 2026
·Updated
A NULL pointer dereference vulnerability exists in the SendingMessage function of SIPp v3.7.3. When SIPp processes specially crafted SIP messages replayed during an active call scenario, insufficient validation of internal message structures can lead to dereferencing a NULL pointer, triggering a segmentation fault. This flaw can be reliably reproduced using a malformed SIP proof-of-concept and AFLNet replay tooling. Under certain memory layout and runtime conditions, this crash may be exploitable to achieve local arbitrary code execution, impacting the integrity and availability of the system running SIPp.
Affected Software
1 affected component
SIPp SIPp
Event History
Jan 8, 2026
Data Sourced
via Red Hat·06:28 AM
DescriptionSeverityAffected Software