Out-of-bounds read in freeswitch - CVE-2026-49475

 

Out-of-bounds read in freeswitch - CVE-2026-49475

Published: June 4, 2026


Vulnerability identifier: #VU133321
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-49475
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds read and out-of-bounds write in switch_stun_packet_parse() when parsing crafted STUN attributes on an ICE-enabled call leg. A remote attacker can send a specially crafted UDP datagram to cause a denial of service.

STUN parsing occurs before the STUN message integrity check, and no ICE password or prior interaction with the call is required.


Affected software

freeswitch

How to mitigate CVE-2026-49475

Install security update from vendor's website.

freeswitch - update to 1.11.0

External References

Related Security Bulletins