CVE-2022-24786

CRITICAL

Pjsip < 2.12 - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that directly uses pjmedia_rtcp_fb_parse_rpsi() will be affected. A patch is available in the `master` branch of the `pjsip/pjproject` GitHub repository. There are currently no known workarounds.

Scores

CVSS v3 9.8
EPSS 0.0074
EPSS Percentile 73.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-125 CWE-787
Status published
Products (3)
debian/debian_linux 9.0
debian/debian_linux 10.0
pjsip/pjsip < 2.12
Published Apr 06, 2022
Tracked Since Feb 18, 2026