#VU125899 Use-after-free in pjsip - CVE-2026-32942
Published: April 14, 2026
pjsip
pjsip
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the ICE session when race conditions occur between session destruction and callbacks. A remote attacker can trigger concurrent session destruction and callback execution to execute arbitrary code.
Any application using the ICE feature is potentially affected.