Skip to main content

Tags CVE-2026-46334

OpenSIPS: Denial of service in SDP bandwidth parsing via QoS SDP cloning

Description

OpenSIPS published GHSA-rh36-mhpv-cx2r for malformed SDP bandwidth-line handling in parser/sdp/sdp_helpr_funcs.c:extract_bwidth(). A missing delimiter can corrupt parsed SDP metadata, which can later crash OpenSIPS when the state is cloned by dialog/QoS handling.

Read more about OpenSIPS: Denial of service in SDP bandwidth parsing via QoS SDP cloning