From 2121ff8ef601d6a9f658d795ea0675184cccc862 Mon Sep 17 00:00:00 2001 From: Milan Kyselica Date: Tue, 24 Mar 2026 19:22:02 +0100 Subject: [PATCH] res_pjsip_pubsub: Add width limit to sscanf in MWI NOTIFY parser The parse_simple_message_summary() function uses sscanf with an unbounded %s format specifier to parse the Message-Account field from incoming SIP NOTIFY bodies into a fixed-size 512-byte stack buffer (PJSIP_MAX_URL_SIZE). A single unauthenticated SIP NOTIFY with a Message-Account value exceeding 512 bytes overflows the buffer, corrupting adjacent stack data and permanently disabling the PJSIP transport layer without crashing the process. Add a width specifier (%511s) to limit the sscanf write to PJSIP_MAX_URL_SIZE - 1 bytes plus the NUL terminator, matching the destination buffer size. Resolves: #GHSA-589g-qgf8-m6mx --- res/res_pjsip_pubsub.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/res/res_pjsip_pubsub.c b/res/res_pjsip_pubsub.c index d2966652ad..437ba9ef28 100644 --- a/res/res_pjsip_pubsub.c +++ b/res/res_pjsip_pubsub.c @@ -3862,7 +3862,7 @@ static int parse_simple_message_summary(char *body, &summary->voice_messages_urgent_new, &summary->voice_messages_urgent_old)) { found_counts = 1; } else { - sscanf(line, "message-account: %s", summary->message_account); + sscanf(line, "message-account: %511s", summary->message_account); } }