PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-57162 pjsip CVE debrief

A stack buffer overflow vulnerability exists in the SRTP/SDES media transport of the PJSIP library when processing a=crypto attributes during SDP offer/answer. This affects applications with SRTP enabled. The issue has been patched via commit a1b707c. Defenders of applications using the PJSIP library with SRTP enabled should assess exposure and prioritize patching to prevent potential application termination or control flow hijack/memory corruption. The vulnerability can be triggered during media negotiation via an incoming SIP INVITE. A remote peer can exploit this by including an excessive number of a=crypto attributes.

Vendor
pjsip
Product
pjproject
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-04
Original CVE updated
2026-09-11
Advisory published
2026-09-04
Advisory updated
2026-09-11

Who should care

Defenders of applications using the PJSIP library with SRTP enabled should assess exposure and prioritize patching to prevent potential application termination or control flow hijack/memory corruption. This includes operators, platform administrators, vulnerability management teams, and security teams responsible for ensuring the security and integrity of affected systems.

Why it matters

Defenders of applications using PJSIP with SRTP enabled should assess exposure and prioritize patching to prevent potential impacts. The vulnerability can be triggered during media negotiation via an incoming SIP INVITE. A remote peer can exploit this by including an excessive number of a=crypto attributes.

  • Potential unexpected application termination
  • Potential control flow hijack/memory corruption
  • Verification of patch application priority

Technical summary

The vulnerability exists in the sdes_encode_sdp() function in transport_srtp_sdes.c. A remote peer can write past the end of a fixed-size array on the stack by including an excessive number of a=crypto attributes in a single media description. This occurs when processing a=crypto attributes from the remote SDP without bounding their number. The issue has been patched via commit a1b707c. Applications that do not enable SRTP are not affected. Impact may range from unexpected application termination to control flow hijack/memory corruption.

Defensive priority

Defenders should prioritize verifying and applying the patch to prevent potential application termination or control flow hijack/memory corruption.

Recommended defensive actions

  • Verify and apply the patch via commit a1b707c
  • Review and update affected applications to ensure SRTP is properly configured
  • Monitor for potential unexpected application termination or control flow hijack/memory corruption
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The vulnerability is caused by a stack buffer overflow in the sdes_encode_sdp() function in transport_srtp_sdes.c. This occurs when processing a=crypto attributes from the remote SDP without bounding their number.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-57162 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-57162

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-57162 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-57162

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.