CVE-2025-65102 Details
Description
PJSIP is a free and open source multimedia communication library. Prior to version 2.16, Opus PLC may zero-fill the input frame as long as the decoder ptime, while the input frame length, which is based on stream ptime, may be less than that. This issue affects PJSIP users who use the Opus audio codec in receiving direction. The vulnerability can lead to unexpected application termination due to a memory overwrite. This issue has been patched in version 2.16.
A buffer overflow vulnerability has been identified in PJSIP versions prior to 2.16, specifically within the Opus audio codec's Packet Loss Concealment (PLC) feature. This vulnerability arises because the PLC can zero-fill the input frame based on the decoder's packet time (ptime), while the actual input frame length, determined by the stream's ptime, may be shorter. As a result, PJSIP applications using the Opus codec in the receiving direction may experience a memory overwrite, leading to an unexpected application termination.
Users can upgrade to PJSIP version 2.16 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 21, 2025CISA-ADP
Assessed Nov 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/pjsip/pjproject/commit/6e9bd2e7d25bba26f852771b40693f45da14fa8f | [email protected] | Source CodeVendor |
| https://github.com/pjsip/pjproject/security/advisories/GHSA-w5vr-39x7-h8g5 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| PJSIP | <= 2.15.1 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2025 | New CVE Received | [email protected] |
Volerion