|
|
Log in / Subscribe / Register

Ubuntu alert USN-8122-1 (pjproject)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8122-1] PJSIP vulnerabilities
Date:  Tue, 24 Mar 2026 21:04:35 +0000
Message-ID:  <E1w58vT-0000pK-SQ@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-8122-1 March 24, 2026 pjproject vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in PJSIP. Software Description: - pjproject: multimedia communication library Details: Youngsung Kim discovered that PJSIP did not properly parse numeric header fields in SIP messages. A remote attacker could use this issue to cause PJSIP to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-16872) Peter Koletzki discovered that PJSIP did not properly handle certain connection requests. A remote attacker could possibly use this issue to cause PJSIP to enter an unrecoverable state and reject further connections, resulting in a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-16875) Alfred Farrugia, Sandro Gauci, and Kevin Harwell discovered that PJSIP did not properly parse certain SDP messages. A remote attacker could possibly use this issue to cause PJSIP to crash, resulting in a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2018-1000098, CVE-2018-1000099) Lauri Vänskä discovered that PJSIP did not verify hostnames when reusing TLS connections. If a remote attacker were able to intercept communication, this flaw could possibly be exploited to view sensitive information. (CVE-2020-15260) It was discovered that PJSIP did not properly handle certain sequences of SDP messages. A remote attacker could possibly use this issue to cause PJSIP to crash, resulting in a denial of service. (CVE-2021-21375) It was discovered that the SSL socket implementation in PJSIP contained a race condition. A remote attacker could possibly use this issue to cause PJSIP to crash, resulting in a denial of service. This issue was only addressed in Ubuntu 18.04 LTS. (CVE-2021-32686) It was discovered that PJSIP did not properly parse certain STUN messages. A remote attacker could use this issue to cause PJSIP to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2021-37706) Uriya Yavnieli discovered that PJSIP did not properly manage memory under certain conditions. A remote attacker could use this issue to cause PJSIP to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2021-43299, CVE-2021-43300, CVE-2021-43301, CVE-2021-43302, CVE-2021-43303) It was discovered that PJSIP did not properly manage memory when processing ICE session credentials. A remote attacker could use this issue to cause PJSIP to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-25994) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS libpj2 2.7.2~dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro libpjmedia2 2.7.2~dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro libpjnath2 2.7.2~dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro libpjsip2 2.7.2~dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro libpjsua2 2.7.2~dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro python-pjproject 2.7.2~dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libpj2 2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1 Available with Ubuntu Pro libpjmedia2 2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1 Available with Ubuntu Pro libpjnath2 2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1 Available with Ubuntu Pro libpjsip2 2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1 Available with Ubuntu Pro libpjsua2 2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8122-1 CVE-2017-16872, CVE-2017-16875, CVE-2018-1000098, CVE-2018-1000099, CVE-2020-15260, CVE-2021-21375, CVE-2021-32686, CVE-2021-37706, CVE-2021-43299, CVE-2021-43300, CVE-2021-43301, CVE-2021-43302, CVE-2021-43303, CVE-2026-25994


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIyBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmnC/EYACgkQcpJm3tlz hgGH/A/4t21+o1oUl8Ot5QzMQkLPeCOJF7lneNuzhXi5+wYBvVQ0BIw1WUDcvl+A et2eIBg67qmRLRlkH5Fs9HJt9lUXj9ZN5bTGARiDUDZkqWoBL9sYXGrc3gwDjsEj hF0QuFzjaa7pSngYqWqELLXpAm2wdGqFc5dX/b4WhUPFLqyx0A/FC8Gq0p94sTZb fBniUL+pZyCM3IDOFUvcav4Bj/roRnpwP6W4HvGkd0L6sISvWkILO2YDVYPUgSdN oVd8MLWXSfKZXM79Ajd7SDvbCq82wLu2PYAZTLValnbPOg/YxwU6Qyxk/mysMNta o7MA94o+kNtVliVSOclhUrdNDQ1CNa6UjL3MDy4VLAOy87nNMG/PlqX6ojOX9dRT iqOFK6m5EuTbs9DDKRP3AA5wFmphO9SRqGupAsBg5ZVA8USpQ3BcwR8bcThzdYYr DXnlix2qeAcZM/5td/n+yheFoQNXHftSIDIkMK38Z0PCXP3ey7rAQ4HUlSQysXw/ YO910GVsq6zz2zEjK1+nRPC+VNMswvgenjSwB7FiV7DbGV36x2111h/ksozobW7i c7JmZZzHyI+UnstMAXL4iMVSUcsFaM/5v7dmrQJuKqn/QRa7p8/Lr97kWGZxxZ0c TC6j1sy2Xa2lYZaj5qUbDnJAj8YD10HLkt4GHuV7OxtmviSE2Q== =eZ7N -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds