Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-28799

Опубликовано: 06 мар. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-free vulnerability exists in PJSIP's event subscription framework (evsub.c) that is triggered during presence unsubscription (SUBSCRIBE with Expires=0). This issue has been patched in version 2.17.

A flaw was found in PJSIP. A remote attacker can exploit a heap use-after-free vulnerability within the event subscription framework by sending a specially crafted message during presence unsubscription. This can lead to a denial of service, making the affected system unavailable.

Отчет

IMPORTANT: A heap use-after-free vulnerability in PJSIP's event subscription framework allows a remote attacker to cause a denial of service. This flaw is triggered by sending a specially crafted message during presence unsubscription, leading to system unavailability. Red Hat products utilizing PJSIP for presence functionality may be affected.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2445116PJSIP: PJSIP: Denial of Service via heap use-after-free in event subscription

EPSS

Процентиль: 21%
0.00285
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-free vulnerability exists in PJSIP's event subscription framework (evsub.c) that is triggered during presence unsubscription (SUBSCRIBE with Expires=0). This issue has been patched in version 2.17.

CVSS3: 7.5
nvd
5 месяцев назад

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-free vulnerability exists in PJSIP's event subscription framework (evsub.c) that is triggered during presence unsubscription (SUBSCRIBE with Expires=0). This issue has been patched in version 2.17.

CVSS3: 7.5
debian
5 месяцев назад

PJSIP is a free and open source multimedia communication library writt ...

EPSS

Процентиль: 21%
0.00285
Низкий

7.5 High

CVSS3