{"id":"CVE-2026-54632","summary":"SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)","details":"SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the STUNAttribute.ParseMessageAttributes, STUNXORAddressAttribute, and STUNAddressAttribute parsing path index untrusted bytes without sufficient length checks, while UdpReceiver.EndReceiveFrom closes the channel when those operations raise a non-socket exception. A remote party can send a single short RTP packet or malformed zero-to-seven-byte STUN address attribute to the shared RTP/ICE socket, including during ICE connectivity checks before DTLS or STUN MESSAGE-INTEGRITY verification, and terminate the active RTP or WebRTC media session. The attacker must reach or learn the advertised ephemeral RTP/ICE port, but no authentication or user interaction is required, and the impact is limited to availability. This issue is fixed in version 10.0.9.","aliases":["GHSA-28gm-jrmw-xx93"],"modified":"2026-09-17T03:30:27.220725859Z","published":"2026-09-14T19:58:30.394Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-20","CWE-755"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54632.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54632.json"},{"type":"ADVISORY","url":"https://github.com/sipsorcery-org/sipsorcery/security/advisories/GHSA-28gm-jrmw-xx93"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54632"},{"type":"FIX","url":"https://github.com/sipsorcery-org/sipsorcery/commit/bdb76cbc0c7216e3126f743fb78e8525af56cea2"},{"type":"FIX","url":"https://github.com/sipsorcery-org/sipsorcery/pull/1677"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sipsorcery-org/sipsorcery","events":[{"introduced":"0"},{"fixed":"bdb76cbc0c7216e3126f743fb78e8525af56cea2"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"10.0.9"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v10.0.8","v10.0.7","v10.0.6","v10.0.5","v10.0.4-pre","v10.0.3","v10.0.2","v10.0.1","v10.0.0","v8.0.23","v8.0.22","v8.0.21-pre","v8.0.20-pre","v8.0.15-pre","v8.0.14","v8.0.13","v8.0.11","v8.0.10","v8.0.9","v8.0.8","v8.0.7","v8.0.6","v8.0.5-pre","vgha001","v8.0.4","v8.0.3","v8.0.2","v8.0.1-pre","v8.0.0","v6.2.4","v6.2.3","v6.2.2","v6.2.1","v6.2.0","v6.1.1-pre","v6.1.0-pre","v6.0.12","v6.0.6","v6.0.5","v6.0.4","v6.0.1-pre","v5.3.3-pre","v5.3.2-pre","v5.3.1-pre","v5.3.0-pre","v5.2.3","v5.2.0","v5.1.8-pre","v5.1.7-pre","v5.1.6-pre","v5.1.5-pre","v5.1.4-pre","v5.1.3-pre","v5.1.2","v5.1.1-pre","v5.1.0","v5.0.32-pre","v5.0.31-pre","v5.0.27-pre","v5.0.26-pre","v5.0.20-pre","v5.0.19-pre","v5.0.18-pre","v5.0.14-pre","v5.0.13-pre","v5.0.12-pre","v5.0.11-pre","v5.0.10-pre","v5.0.9-pre","v5.0.8-pre","v5.0.7-pre","v5.0.6-pre","v5.0.5-pre","v5.0.4-pre","v5.0.3","v5.0.2","v5.0.1","v5.0.0","v4.0.91-pre","v4.0.90-pre","v4.0.89-pre","v4.0.88-pre","v4.0.87-pre","v4.0.86-pre","v4.0.85-pre","v4.0.84-pre","v4.0.83-pre","v4.0.82-pre","v4.0.81-pre","v4.0.80-pre","v4.0.79-pre","v4.0.78-pre","v4.0.77-pre","v4.0.76-pre","v4.0.75-pre","v4.0.74-pre","v4.0.71-pre","v4.0.70-pre","v4.0.69-pre","v4.0.68-pre","v4.0.67-pre","v4.0.61-pre","v4.0.60-pre","v4.0.59-pre","v4.0.58-pre","v4.0.55-pre","v4.0.51-pre","v4.0.50-pre","v4.0.49-pre","v4.0.47-pre","v4.0.46-pre","v4.0.45-pre","v4.0.44-pre","v4.0.43-pre","v4.0.42-pre","v4.0.41-pre","v4.0.40-pre","v4.0.35-pre","v4.0.34-pre","v4.0.33-pre","v4.0.32-pre","v4.0.31-pre","v4.0.30-pre","v4.0.28-pre","v4.0.13-pre","v4.0.8-rc","v4.0.7-rc","v4.0.6-rc","v4.0.5-rc","v4.0.4-rc","4.0.3-rc","v4.0.2-rc","v4.0.1-rc","v4.0.0-rc","v3.6.0","v3.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54632.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}