Use-after-free in pjsip - CVE-2026-32942
Published: April 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the ICE session when race conditions occur between session destruction and callbacks. A remote attacker can trigger concurrent session destruction and callback execution to execute arbitrary code.
Any application using the ICE feature is potentially affected.
Affected software
Asterisk Open Source
Certified Asterisk
How to mitigate CVE-2026-32942
Asterisk Open Source - addressed in versions 20.19.0, 21.12.2, 22.9.0, 23.3.0
Certified Asterisk - addressed in versions 20.7-cert10, 22.8-cert2