CVE-2025-65102

HIGH

PJSIP <2.16 - Memory Corruption

Title source: llm
STIX 2.1

Description

PJSIP is a free and open source multimedia communication library. Prior to version 2.16, Opus PLC may zero-fill the input frame as long as the decoder ptime, while the input frame length, which is based on stream ptime, may be less than that. This issue affects PJSIP users who use the Opus audio codec in receiving direction. The vulnerability can lead to unexpected application termination due to a memory overwrite. This issue has been patched in version 2.16.

Scores

CVSS v4 8.7
EPSS 0.0006
EPSS Percentile 18.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-120
Status published
Products (1)
pjsip/pjproject < 2.16
Published Nov 21, 2025
Tracked Since Feb 18, 2026