Stack Buffer Overflow in sngrep SIP Packet Processing by Irontec
CVE-2026-90558
9.3CRITICAL
What is CVE-2026-90558?
The sngrep application, up to version 1.8.4, contains a stack buffer overflow vulnerability due to improper handling of SIP headers that exceed the 255-byte limit. Attackers can exploit this flaw by sending specially crafted SIP packets with oversized Call-ID or X-Call-ID headers. The resulting stack overflow may lead to crashes or the execution of arbitrary code during the processing of these packets, posing significant security risks to systems using this application.
Affected Version(s)
sngrep 0 <= 1.8.4
