[OpenSIPS-Devel] [OpenSIPS/opensips] 99458d: fixed stack buffer overflow in $(cT[*]) pvar

Bogdan Andrei IANCU noreply at github.com
Mon Jun 15 14:21:08 UTC 2026


  Branch: refs/heads/4.0
  Home:   https://github.com/OpenSIPS/opensips
  Commit: 99458d6c1d079062c10076ec35e746635abf9111
      https://github.com/OpenSIPS/opensips/commit/99458d6c1d079062c10076ec35e746635abf9111
  Author: Bogdan-Andrei Iancu <bogdan at opensips.org>
  Date:   2026-06-15 (Mon, 15 Jun 2026)

  Changed paths:
    M pvar.c

  Log Message:
  -----------
  fixed stack buffer overflow in $(cT[*]) pvar

Credits for reporting and fixing go to Yiyi Wang, Tsinghua University (wangyiyi25 at mails.tsinghua.edu.cn)
https://github.com/OpenSIPS/opensips/security/advisories/GHSA-w522-9gcp-274p

(cherry picked from commit fbef00a7bb4dfc5f0f24528d123beac128462827)



To unsubscribe from these emails, change your notification settings at https://github.com/OpenSIPS/opensips/settings/notifications



More information about the Devel mailing list