PJSIP is a free and open source multimedia communication library. Prior to version 2.16, Opus PLC may zero-fill the input frame as long as the decoder ptime, while the input frame length, which is based on stream ptime, may be less than that. This issue affects PJSIP users who use the Opus audio codec in receiving direction. The vulnerability can lead to unexpected application termination due to a memory overwrite. This issue has been patched in version 2.16.
History

Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Pjsip
Pjsip pjsip
Vendors & Products Pjsip
Pjsip pjsip

Fri, 21 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Nov 2025 21:45:00 +0000

Type Values Removed Values Added
Description PJSIP is a free and open source multimedia communication library. Prior to version 2.16, Opus PLC may zero-fill the input frame as long as the decoder ptime, while the input frame length, which is based on stream ptime, may be less than that. This issue affects PJSIP users who use the Opus audio codec in receiving direction. The vulnerability can lead to unexpected application termination due to a memory overwrite. This issue has been patched in version 2.16.
Title PJSIP is vulnerable to buffer overflow in Opus PLC
Weaknesses CWE-120
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-21T21:36:58.375Z

Updated: 2025-11-21T21:55:09.092Z

Reserved: 2025-11-17T20:55:34.693Z

Link: CVE-2025-65102

cve-icon Vulnrichment

Updated: 2025-11-21T21:55:04.693Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-21T22:16:32.740

Modified: 2025-11-25T22:16:42.557

Link: CVE-2025-65102

cve-icon Redhat

No data.