CVE-2022-23608 Details
Description
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions up to and including 2.11.1 when in a dialog set (or forking) scenario, a hash key shared by multiple UAC dialogs can potentially be prematurely freed when one of the dialogs is destroyed . The issue may cause a dialog set to be registered in the hash table multiple times (with different hash keys) leading to undefined behavior such as dialog list collision which eventually leading to endless loop. A patch is available in commit db3235953baa56d2fb0e276ca510fefca751643f which will be included in the next release. There are no known workarounds for this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| teluu pjsip | <= 2.11.1 |
CPE
Remediation
| |
| asterisk certified asterisk | < 16.8.0 16.8.0 cert1 16.8.0 cert10 16.8.0 cert11 16.8.0 cert12 16.8.0 cert2 16.8.0 cert3 16.8.0 cert4 16.8.0 cert5 16.8.0 cert6 16.8.0 cert7 16.8.0 cert8 16.8.0 cert9 |
CPE
Remediation
| |
| sangoma asterisk | >= 16.0.0, < 16.24.1 >= 18.0.0, < 18.10.1 >= 19.0.0, < 19.2.1 |
CPE
Remediation
| |
| debian debian linux | 9.0 10.0 |
CPE
Remediation
| |
Change History
17 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 4, 2025 | CVE Modified | CVE |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Aug 30, 2023 | CVE Modified | [email protected] |
| Feb 2, 2023 | Modified Analysis | [email protected] |
| Nov 18, 2022 | CVE Modified | [email protected] |
| Nov 17, 2022 | CVE Modified | [email protected] |
| Nov 16, 2022 | Modified Analysis | [email protected] |
| Oct 31, 2022 | CVE Modified | [email protected] |
| Apr 25, 2022 | Modified Analysis | [email protected] |
| Mar 31, 2022 | CVE Modified | [email protected] |
| Mar 28, 2022 | CVE Modified | [email protected] |
| Mar 10, 2022 | CVE Modified | [email protected] |
| Mar 4, 2022 | CVE Modified | [email protected] |
| Mar 1, 2022 | Initial Analysis | [email protected] |