Out-of-Bounds Write in PJSIP Media Library
CVE-2026-77396
6.9MEDIUM
What is CVE-2026-77396?
The PJSIP library, an open-source multimedia communication tool, possesses a vulnerability in its AVI parser that could lead to serious memory corruption issues. In versions 2.17 and earlier, the library improperly handles the length of video chunks during playback of crafted AVI files. This oversight allows attackers to manipulate memory via an out-of-bounds write beyond the allocated heap space. Although typical usage may crash the application, a depth of exploitation exists for applications processing untrusted AVI sources, making this flaw particularly dangerous. As no patched version has been released yet, users should exercise caution when handling media through PJSIP.
Affected Version(s)
pjproject <= 2.17
