Hi,
The following vulnerability was published for asterisk.
CVE-2026-77396[0]:
| PJSIP is a free and open source multimedia communication library
| written in C. In 2.17 and earlier, the PJSIP AVI parser in
| pjmedia/src/pjmedia/avi_player.c uses an input-file video chunk
| length as the number of bytes copied into a frame buffer whose
| capacity is derived from the declared media dimensions. A crafted
| AVI file can therefore cause an attacker-controlled out-of-bounds
| write past the heap allocation when an application plays the file or
| pulls its frames. The existing size assertion does not protect
| production release builds, where assertions are disabled. Typical
| local playback can crash the process, while applications that accept
| untrusted AVI sources expose a stronger memory-corruption condition.
| No fixed version is available as of this review.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-77396
https://www.cve.org/CVERecord?id=CVE-2026-77396
[1] https://github.com/pjsip/pjproject/security/advisories/GHSA-6p2p-5wf8-h5hr
Regards,
Salvatore