Out-of-Bounds Write in PJSIP Media Library
CVE-2026-77396

6.9MEDIUM

Key Information:

Vendor

Pjsip

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-77396?

The PJSIP library, an open-source multimedia communication tool, possesses a vulnerability in its AVI parser that could lead to serious memory corruption issues. In versions 2.17 and earlier, the library improperly handles the length of video chunks during playback of crafted AVI files. This oversight allows attackers to manipulate memory via an out-of-bounds write beyond the allocated heap space. Although typical usage may crash the application, a depth of exploitation exists for applications processing untrusted AVI sources, making this flaw particularly dangerous. As no patched version has been released yet, users should exercise caution when handling media through PJSIP.

Affected Version(s)

pjproject <= 2.17

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.