{"id":"CVE-2026-26967","summary":"PJSIP has a Heap-based Buffer Overflow vulnerability in its H.264 unpacketizer","details":"PJSIP is a free and open source multimedia communication library written in C. In versions 2.16 and below, there is a critical Heap-based Buffer Overflow vulnerability in PJSIP's H.264 unpacketizer. The bug occurs when processing malformed SRTP packets, where the unpacketizer reads a 2-byte NAL unit size field without validating that both bytes are within the payload buffer bounds. The vulnerability affects applications that receive video using H.264. A patch is available at https://github.com/pjsip/pjproject/commit/f821c214e52b11bae11e4cd3c7f0864538fb5491.","aliases":["GHSA-x2hc-6969-g8v6"],"modified":"2026-08-12T15:32:04.669033Z","published":"2026-02-20T00:26:54.397Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26967.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"f821c214e52b11bae11e4cd3c7f0864538fb5491"}]}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26967.json"},{"type":"ADVISORY","url":"https://github.com/pjsip/pjproject/security/advisories/GHSA-x2hc-6969-g8v6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26967"},{"type":"FIX","url":"https://github.com/pjsip/pjproject/commit/f821c214e52b11bae11e4cd3c7f0864538fb5491"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pjsip/pjproject","events":[{"introduced":"0"},{"fixed":"5a457451fa2712ba18e12b01738e8ff3af2b26fd"},{"fixed":"f821c214e52b11bae11e4cd3c7f0864538fb5491"}],"database_specific":{"cpe":"cpe:2.3:a:pjsip:pjsip:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.17"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["2.16","2.15","2.14","2.13","2.12","2.11","2.10"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26967.json","vanir_signatures_modified":"2026-08-12T15:32:04Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/f821c214e52b11bae11e4cd3c7f0864538fb5491","target":{"file":"pjmedia/src/pjmedia-codec/h264_packetizer.c","function":"pjmedia_h264_unpacketize"},"deprecated":false,"digest":{"function_hash":"174921199561578382857004597551213349124","length":3509},"id":"CVE-2026-26967-6c6abe9b"},{"digest":{"line_hashes":["174508775060688208186196933156386257496","269120899693158134564375044710920344784","15752697100210992036560622550029801042","207095924632289926696655095349060998272"],"threshold":0.9},"id":"CVE-2026-26967-fffb1e22","signature_type":"Line","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/f821c214e52b11bae11e4cd3c7f0864538fb5491","target":{"file":"pjmedia/src/pjmedia-codec/h264_packetizer.c"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U"}]}