Out-of-Bounds Read Vulnerability in Belledonne Communications bcg729 Product
CVE-2026-71980
8.7HIGH
What is CVE-2026-71980?
Belledonne Communications' bcg729, up to version 1.1.2, contains a vulnerability in the decodeSIDframe() function, allowing unauthenticated network-adjacent attackers to exploit this weakness. By sending a zero-length comfort-noise RTP payload, attackers can trigger an integer underflow during filter order calculations, leading to an out-of-bounds read from a zero-byte buffer. This results in potential media process termination or silent exploitation of adjacent heap memory.
Affected Version(s)
bcg729 0 <= 1.1.2
