🛡️ CVE-2022-23608
🟠 CVSS 8.1 — High ✅ No Known Exploit CWE-416 NVD
8.1
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions up to and including 2.11.1 when in a dialog set (or forking) scenario, a hash key shared by multiple UAC dialogs can potentially be prematurely freed when one of the dialogs is destroyed . The issue may cause a dialog set to be registered in the hash table multiple times (with different hash keys) leading to undefined behavior such as dialog list collision which eventually leading to endless loop. A patch is available in commit db3235953baa56d2fb0e276ca510fefca751643f which will be included in the next release. There are no known workarounds for this issue.

Details

Severity HIGH
CVSS Score 8.1
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE CWE-416
Public Exploit ✅ No
Source NVD
Published 2022-02-22
Updated 2026-06-08
Modified 2025-11-04

Affected Packages

Software From version Fixed in
asterisk 19.0.0 19.2.1
certified-asterisk
debian-linux
pjsip 2.11.1

References

Mailing List, Patch, Third Party Advisory http://seclists.org/fulldisclosure/2022/Mar/1
Mailing List, Patch, Third Party Advisory http://seclists.org/fulldisclosure/2022/Mar/1

Patch Gap Protection

Running software with known vulnerabilities?

BotEraser can help reduce exposure by blocking IPs associated with exploit activity — even before a patch is available.

Start Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.