Skip to content

Missing unreleased of locks in failure cases

High
sauwming published GHSA-8fmx-hqw7-6gmc Jan 4, 2022

Package

No package listed

Affected versions

2.11.1 or lower

Patched versions

2.12 or later

Description

In various parts of PJSIP, when error/failure occurs, it is found that the function returns without releasing the currently held locks. This could result in a system deadlock, which cause a denial of service for the users.

Impact

It affects all users of PJSIP that use the affected components.

Patches

The patch is available as commit 1aa2c0e in the master branch.

For more information

If you have any questions or comments about this advisory:
Email us at security@pjsip.org

Severity

High

CVE ID

CVE-2021-41141

Weaknesses

No CWEs

Credits