#1149963 asterisk: CVE-2026-77396

Package:
src:asterisk
Source:
src:asterisk
Submitter:
Salvatore Bonaccorso
Date:
2026-10-04 19:17:02 UTC
Severity:
normal
Tags:
#1149963#5
Date:
2026-10-04 19:15:31 UTC
From:
To:
Hi,

The following vulnerability was published for asterisk.

CVE-2026-77396[0]:
| PJSIP is a free and open source multimedia communication library
| written in C. In 2.17 and earlier, the PJSIP AVI parser in
| pjmedia/src/pjmedia/avi_player.c uses an input-file video chunk
| length as the number of bytes copied into a frame buffer whose
| capacity is derived from the declared media dimensions. A crafted
| AVI file can therefore cause an attacker-controlled out-of-bounds
| write past the heap allocation when an application plays the file or
| pulls its frames. The existing size assertion does not protect
| production release builds, where assertions are disabled. Typical
| local playback can crash the process, while applications that accept
| untrusted AVI sources expose a stronger memory-corruption condition.
| No fixed version is available as of this review.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-77396
https://www.cve.org/CVERecord?id=CVE-2026-77396
[1] https://github.com/pjsip/pjproject/security/advisories/GHSA-6p2p-5wf8-h5hr

Regards,
Salvatore