CVE-2026-57160 Overview
CVE-2026-57160 is an off-by-one buffer overflow [CWE-193] in PJSIP, the open source multimedia communication library maintained by Teluu. The flaw resides in pjsip_generic_array_hdr_print() in pjsip/src/pjsip/sip_msg.c, which serializes generic SIP array headers such as Allow, Require, Supported, and Unsupported. Under specific output-buffer boundary conditions, the function writes one byte past the end of the destination buffer. The issue is reachable in applications that parse and re-serialize inbound SIP requests, including proxies, session border controllers (SBCs), and back-to-back user agents (B2BUAs). The upstream project patched the defect in commit d6a0e7f.
Critical Impact
A remote SIP peer can influence message serialization to trigger a one-byte out-of-bounds write in SIP infrastructure components. Code execution and information disclosure have not been demonstrated.
Affected Products
- Teluu PJSIP (pjproject) versions prior to commit d6a0e7f
- SIP proxies, SBCs, and B2BUAs built on PJSIP
- Downstream applications performing SIP message re-serialization using PJSIP
Discovery Timeline
- 2026-09-04 - CVE-2026-57160 published to the National Vulnerability Database
- 2026-09-11 - Last updated in NVD database
Technical Details for CVE-2026-57160
Vulnerability Analysis
The defect is a classic off-by-one write in a serialization routine. pjsip_generic_array_hdr_print() produces the textual representation of SIP array headers into a caller-supplied output buffer. When the remaining buffer space aligns with specific header value boundaries, the function emits one extra byte beyond the tracked buffer end. Because PJSIP typically allocates message buffers from pools with alignment slack, the extra byte often falls within that slack region, which is why the observable impact is limited to a low-integrity and low-availability write rather than a corrupted adjacent object. Exploitation surface expands in server-side deployments such as proxies and SBCs, where an untrusted remote peer supplies header content that gets re-serialized on egress.
Root Cause
The serializer wrote the fixed characters ':' and ' ' directly through the output pointer without validating remaining buffer capacity. Callers that supplied a buffer whose length matched the serialized header size minus these trailing bytes triggered the one-byte overflow. The fix replaces raw pointer writes with the bounds-checked copy_advance_char_check macro.
Attack Vector
A remote unauthenticated peer sends a crafted SIP request containing generic array headers (Allow, Require, Supported, or Unsupported) to a PJSIP-based intermediary. When the intermediary re-serializes the request for onward transmission, the boundary-triggered off-by-one write occurs in the output buffer. No user interaction or authentication is required.
&hdr->sname : &hdr->name;
copy_advance(p, (*hname));
- *p++ = ':';
- *p++ = ' ';
+ copy_advance_char_check(p, ':');
+ copy_advance_char_check(p, ' ');
if (hdr->count > 0) {
unsigned i;
// Source: https://github.com/pjsip/pjproject/commit/d6a0e7f76611c3a6f530ee051e3e7a622bb1748c
// The patch replaces unchecked pointer writes with the bounds-checked
// copy_advance_char_check macro, preventing the one-byte overflow.
Detection Methods for CVE-2026-57160
Indicators of Compromise
- Unexplained crashes or memory corruption reports in PJSIP-based proxies, SBCs, or B2BUAs handling SIP traffic
- Inbound SIP requests containing unusually structured Allow, Require, Supported, or Unsupported headers from untrusted peers
- AddressSanitizer or similar tooling reporting a one-byte heap or pool overflow in pjsip_generic_array_hdr_print()
Detection Strategies
- Inventory all deployed applications and appliances built on Teluu PJSIP and verify the linked commit against d6a0e7f
- Build PJSIP-based services with AddressSanitizer in staging to surface boundary writes during fuzzed SIP traffic replay
- Correlate SIP parser error logs with peer IP addresses to identify anomalous senders repeatedly crafting boundary-condition headers
Monitoring Recommendations
- Enable verbose SIP transaction logging on proxies and SBCs to capture header content associated with parser faults
- Monitor process stability metrics (restarts, segmentation faults, watchdog resets) on SIP infrastructure components
- Track upstream advisories from the PJSIP GitHub Security Advisories page for related fixes
How to Mitigate CVE-2026-57160
Immediate Actions Required
- Update PJSIP source trees to include commit d6a0e7f and rebuild all dependent binaries and appliances
- Coordinate with vendors of SIP appliances (SBCs, proxies, softphones) to confirm their PJSIP version and patch status
- Restrict SIP signaling exposure so that only trusted peers can reach PJSIP-based intermediaries where feasible
Patch Information
The fix is available in upstream commit pjproject d6a0e7f. Additional context is published in GitHub Security Advisory GHSA-277r-3q2j-mxcw. Rebuild all statically linked consumers of PJSIP after applying the patch.
Workarounds
- Apply the upstream patch or backport the copy_advance_char_check change to older PJSIP branches
- Filter or normalize inbound SIP Allow, Require, Supported, and Unsupported headers at the network edge to reduce attacker control over serialized content
- Enforce peer authentication and IP allowlisting on SIP interfaces to limit exposure to untrusted senders
# Rebuild PJSIP from a patched source tree
git clone https://github.com/pjsip/pjproject.git
cd pjproject
git checkout d6a0e7f76611c3a6f530ee051e3e7a622bb1748c
./configure && make dep && make
sudo make install
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
