Description
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions up to and including 2.11.1 when in a dialog set (or forking) scenario, a hash key shared by multiple UAC dialogs can potentially be prematurely freed when one of the dialogs is destroyed . The issue may cause a dialog set to be registered in the hash table multiple times (with different hash keys) leading to undefined behavior such as dialog list collision which eventually leading to endless loop. A patch is available in commit db3235953baa56d2fb0e276ca510fefca751643f which will be included in the next release. There are no known workarounds for this issue.
References (11)
Core 11
Core References
Mailing List, Patch, Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Mar/1
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/03/msg00035.html
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/03/msg00040.html
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202210-37
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/11/msg00021.html
Third Party Advisory vendor-advisory
https://www.debian.org/security/2022/dsa-5285
Mailing List mailing-list
https://lists.debian.org/debian-lts-announce/2023/08/msg00038.html
Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/166226/Asterisk-Project-Security-Advisory-AST-2022-005.html
Patch, Third Party Advisory
https://github.com/pjsip/pjproject/commit/db3235953baa56d2fb0e276ca510fefca751643f
Issue Tracking, Patch, Third Party Advisory
https://github.com/pjsip/pjproject/security/advisories/GHSA-ffff-m5fm-qm62
Scores
CVSS v3
8.1
EPSS
0.0078
EPSS Percentile
73.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-416
Status
published
Products (6)
asterisk/certified_asterisk
16.8.0 cert1 (12 CPE variants)
asterisk/certified_asterisk
< 16.8.0
debian/debian_linux
9.0
debian/debian_linux
10.0
sangoma/asterisk
16.0.0 - 16.24.1
teluu/pjsip
< 2.11.1
Published
Feb 22, 2022
Tracked Since
Feb 18, 2026