Security Advisory

CVE-2026-26203

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-02-19 19:28:58
Last updated 2026-02-19 21:22:31
Assigner GitHub_M
State PUBLISHED

Description

PJSIP is a free and open source multimedia communication library. Versions prior to 2.17 have a critical heap buffer underflow vulnerability in PJSIPs H.264 packetizer. The bug occurs when processing malformed H.264 bitstreams without NAL unit start codes, where the packetizer performs unchecked pointer arithmetic that can read from memory located before the allocated buffer. Version 2.17 contains a patch for the issue.