NULL pointer dereference in pjsip - #VU150688

 

NULL pointer dereference in pjsip - #VU150688

Published: September 17, 2026 / Updated: September 17, 2026


Vulnerability identifier: #VU150688
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-476
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the UPnP IGD client's download_igd_xml() function when processing a device description containing an empty serviceType element. A remote attacker can reply to an SSDP M-SEARCH request with a crafted device description to cause a denial of service.

UPnP support must be built in and explicitly enabled for the vulnerable code path to be reachable.


Affected software

pjsip

Remediation

Install security update from vendor's website.

pjsip - update to 2.18

External References

Related Security Bulletins