{"id":"DEBIAN-CVE-2026-29068","details":"PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack buffer overflow vulnerability when pjmedia-codec parses an RTP payload contain more frames than the caller-provided frames can hold. This issue has been patched in version 2.17.","modified":"2026-04-28T20:31:27.776567Z","published":"2026-03-06T07:16:02.607Z","upstream":["CVE-2026-29068"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-29068"}],"affected":[{"package":{"name":"asterisk","ecosystem":"Debian:11","purl":"pkg:deb/debian/asterisk?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:16.16.1~dfsg+~2.10-1","1:16.16.1~dfsg+~2.10-2","1:16.16.1~dfsg-1","1:16.16.1~dfsg-1+deb11u1","1:16.16.1~dfsg-1+deb11u1~bpo10+1","1:16.16.1~dfsg-2","1:16.16.1~dfsg-3","1:16.16.1~dfsg-4","1:16.23.0~dfsg+~2.10-1","1:16.23.0~dfsg+~cs6.10.20220309-1","1:16.23.0~dfsg+~cs6.10.20220309-2","1:16.23.0~dfsg+~cs6.10.40431411-1","1:16.28.0~dfsg-0+deb11u1","1:16.28.0~dfsg-0+deb11u2","1:16.28.0~dfsg-0+deb11u3","1:16.28.0~dfsg-0+deb11u4","1:16.28.0~dfsg-0+deb11u5","1:16.28.0~dfsg-0+deb11u6","1:16.28.0~dfsg-0+deb11u7","1:16.28.0~dfsg-0+deb11u8","1:16.28.0~dfsg-0+deb11u9","1:18.10.0~dfsg+~cs6.10.40431411-1","1:18.10.0~dfsg+~cs6.10.40431411-2","1:18.10.1~dfsg+~cs6.10.40431411-1","1:18.11.1~dfsg+~cs6.10.40431413-1","1:18.11.2~dfsg+~cs6.10.40431413-1","1:18.12.0~dfsg+~cs6.12.40431413-1","1:18.14.0~dfsg+~cs6.12.40431414-1","1:18.14.0~~rc1~dfsg+~cs6.12.40431414-1","1:18.9.0~dfsg+~cs6.10.40431411-1","1:20.0.0~dfsg+~cs6.12.40431414-1","1:20.0.0~dfsg+~cs6.12.40431414-2","1:20.0.0~~rc1~dfsg+~cs6.12.40431414-1","1:20.0.0~~rc2~dfsg+~cs6.12.40431414-1","1:20.0.1~dfsg+~cs6.12.40431414-1","1:20.1.0~dfsg+~cs6.12.40431414-1","1:20.1.0~~rc2~dfsg+~cs6.12.40431414-1","1:20.2.1~dfsg+~cs6.13.40431413-1","1:20.3.0~dfsg+~cs6.13.40431413-1","1:20.4.0~dfsg+~cs6.13.40431414-1","1:20.4.0~dfsg+~cs6.13.40431414-2","1:20.5.0~dfsg+~cs6.13.40431414-1","1:20.5.1~dfsg+~cs6.13.40431414-1","1:20.5.2~dfsg+~cs6.13.40431414-1","1:20.6.0~dfsg+~cs6.13.40431414-1","1:20.6.0~dfsg+~cs6.13.40431414-2","1:20.8.1~dfsg+~cs6.14.40431414-1","1:20.9.3~dfsg+~cs6.14.60671435-1","1:22.0.0~dfsg+~cs6.14.60671435-1","1:22.0.0~~rc2~dfsg+~cs6.14.60671435-1","1:22.1.0~dfsg+~cs6.14.60671435-1","1:22.1.1~dfsg+~cs6.14.60671435-1","1:22.2.0~dfsg+~cs6.15.60671435-1","1:22.2.0~dfsg+~cs6.15.60671435-2","1:22.3.0~dfsg+~cs6.15.60671435-1","1:22.3.0~~rc1~dfsg+~cs6.15.60671435-1","1:22.4.1~dfsg+~cs6.15.60671435-1","1:22.4.1~dfsg+~cs6.15.60671435-2","1:22.5.1~dfsg+~cs6.15.60671435-1","1:22.5.2~dfsg+~cs6.15.60671435-1","1:22.6.0~dfsg+~cs6.15.60671435-1","1:22.7.0~dfsg+~cs6.15.60671435-1","1:22.8.0+dfsg+~cs6.15.60671435-1","1:22.8.2+dfsg+~cs6.15.60671435-1","1:22.9.0+dfsg+~cs6.16.60671434-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-29068.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}