CVE-2026-26203
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-26203 is a heap buffer underflow (use-after-free) vulnerability in PJSIP's H.264 packetizer, affecting all versions of the pjmedia-video package prior to 2.17. The flaw was discovered via PJSIP's new fuzz-video fuzzer and publicly disclosed on February 19, 2026, with a patch released in version 2.17. It carries a CVSS v3.1 base score of 6.5 (Medium) with a local attack vector (Red Hat Advisory, GitHub Advisory).

Technical details

The root cause is improper pointer arithmetic in pjmedia/src/pjmedia-codec/h264_packetizer.c during H.264 fragmented NAL unit packetization (CWE-416: Use-After-Free; CWE-825: Expired Pointer Dereference). When processing malformed H.264 bitstreams that lack NAL unit start codes, the packetizer computes p = nal_start - pktz->cfg.mtu without first verifying that nal_start is sufficiently ahead of the buffer start, allowing reads from memory before the allocated heap buffer. The fix adds bounds checks to validate nal_start position and confirm the FU-A fragmentation indicator before performing pointer arithmetic (GitHub Commit, GitHub Advisory). Exploitation requires local access with low privileges and targets applications using PJSIP with H.264 packetization modes other than single NAL.

Impact

Successful exploitation can cause a heap-use-after-free condition leading to unexpected application termination (denial of service). Out-of-bounds memory reads may also expose sensitive heap memory contents to a local attacker. The vulnerability is scoped to applications that send video using H.264 with non-single-NAL packetization modes; no integrity impact is expected, and there is no evidence of remote exploitability (GitHub Advisory, Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.014% (0.000140), reflecting a very low probability of exploitation in the near term (Red Hat Advisory).

Mitigation and workarounds

Upgrade PJSIP to version 2.17 or later, which contains the patch (commit 5aee54f) addressing the bounds-checking flaw in the H.264 packetizer (GitHub Commit). For organizations unable to patch immediately, restrict local access to systems running vulnerable PJSIP versions and limit privileges of accounts that can interact with H.264 video processing functionality. Prioritize patching deployments where PJSIP is used with H.264 in non-single-NAL packetization modes, as these are the configurations directly affected (GitHub Advisory, Red Hat Bugzilla).

Community reactions

Red Hat has tracked the issue via Bugzilla (Bug 2441087) and published a security advisory, classifying it as medium severity. The PJSIP project credited security researcher arthurscchan as the finder, with the vulnerability discovered through PJSIP's new fuzz-video fuzzer (GitHub Advisory, Red Hat Bugzilla). No significant broader media coverage or notable community discussion has been observed.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

sid

asterisk: 1:22.10.0+dfsg+~cs6.17.60671434-1

Fixed

Ubuntu

Affected

bionic (esm-apps)

pjproject

Affected

xenial (esm-apps-legacy)

pjproject

Affected

Alpine

Fixed

edge

pjproject: 2.17-r0

Fixed

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management