StreamingMemeStreamingMeme
LeaderboardsEventsSubmit News
SUBSCRIBE

Daily Brief

The streaming industry in your inbox every morning.

Daily Brief

The streaming industry in your inbox every morning.

StreamingMeme

The streaming technology industry news aggregator.

About UsNewsletterSubmit News
© 2026 StreamingMeme. All rights reserved.
← Encoding & Software
EncodingTechnical Development

PJSIP patches VP9 RTP heap read flaw in 2.17

PJSIP patches VP9 RTP heap read flaw in 2.17
GitHub

A moderate severity heap out-of-bounds read vulnerability has been disclosed in the PJSIP open-source project. The vulnerability (CVE-2026-34235) exists in the VP9 RTP unpacketizer in versions 2.16 and lower, where insufficient bounds checking on crafted VP9 payloads can cause reads beyond the allocated buffer. A patch has been made available in version 2.17.

Key Takeaways

  • Affected versions are pjproject 2.16 or lower; patched version is 2.17.
  • The bug sits in the VP9 RTP unpacketizer and triggers during parsing of crafted VP9 Scalability Structure data.
  • PJSIP says applications with video support enabled (`PJMEDIA_HAS_VIDEO`) that receive VP9 RTP media are potentially affected.
  • The published patch is commit f4c7d08 in the master branch.
  • PJSIP lists disabling the VP9 codec as a workaround if it is not needed.

Why It Matters

This is an open-source media stack issue that can affect any PJSIP application with video support enabled and VP9 RTP traffic. For streaming teams using pjproject in signaling or media pipelines, the immediate task is version checking: 2.16 and earlier are affected, while 2.17 contains the fix. The broader takeaway is that codec parsing remains a security-sensitive part of the streaming stack, especially where payload descriptors are handled before video is decoded. The concrete watch item is whether downstream builds move to 2.17 or ship VP9 disabled as a stopgap.


Read full article at github.com

Related Articles

The Broadcast Bridge: Decoding H.264: Navigating AVC Profiles, Levels, and Signaling for Streaming
wTVision: A Bola TV Migrates Online Channel to Broadcast with Redundant Playout
wTVision: wTVision uses seat sensors for real-time audience voting on Tele 5 talent show

Newest

about 18 hours ago
Pro AVL Central: Blackmagic Debuts Fairlight Live, Boosts DaVinci Resolve 21 with AI and Photo Tools
about 18 hours ago
NewscastStudio: MXL Rapid Development Challenges Traditional Broadcast Standardization
about 18 hours ago
Smpte: SMPTE Media Technology Summit Returns to Pasadena November 2026
about 18 hours ago
Tech Times: Let's Encrypt charts Merkle Tree Certificate path for post-quantum TLS
about 18 hours ago
cvefeed.io: Netty Fixes Undetected Stream Truncation in Chunked OHTTP Messages
about 18 hours ago
Ietf: IETF Advances Network Protocol Drafts for Streaming Infrastructure
about 18 hours ago
Forasoft: Fora Soft Launches Monthly WebRTC & Real-time Video Engineering Report
about 18 hours ago
Atis: ATIS Outlines Practical Roadmap for North American 5G Standalone Deployment
about 18 hours ago
Youtube: 3GPP Advances 5G-Advanced with Release 19, Commences 6G Studies
about 18 hours ago
3gpp: 3GPP Release 6 Refines Radio Network Rules for Cell Handover, Measurement
about 18 hours ago
3gpp: 3GPP Details 20 Mobile Telecommunications Releases, Including Open Release 21
about 18 hours ago
Pro AVL Central: Matrox Launches IPMX-Ready Maevex MGX Series for 4K60 AV-over-IP
about 18 hours ago
GitHub: OpenMOSS Expands MOSS-TTS Family with Nano Model, Enhanced SoundEffects
about 18 hours ago
NewscastStudio: Media Exchange Layer (MXL) Complements ST 2110 for Software-Defined Production
about 18 hours ago
Penligent Security Blog – AI-Driven Hacking Tutorials, Exploit PoCs & Cybersecurity Research: HTTP/2 Bomb Vulnerability: Apache, Envoy, Nginx Face DoS Risk
about 18 hours ago
SamsungNewsroom: Samsung Galaxy S26 Series Introduces Cine LUT for Accessible Mobile Color Grading
about 18 hours ago
KORE1: Spotify Engineers: A Six-Profile Map for Strategic Hiring
about 18 hours ago
TV Tech: GatesAir Establishes Brazil Hub for DTV+ Rollout, Local Support
about 19 hours ago
Telecompaper: Technicolor Joins Pearl TV Initiative for Affordable ATSC 3.0 Converter Boxes
about 19 hours ago
law360: Generative AI, SEPs Drive IP Licensing Activity from May 22-June 4

Upcoming Events

Jun
8–11
NEM Dubrovnikhttps://neweumarket.com/dubrovnik/
Jun
11–12
Arctic 15https://arctic15.com/
Jun
13–19
InfoCommhttps://www.infocommshow.org/
Jun
16–19
Stream TV Show (formerly the Pay TV Show)https://www.streamtvshow.com/
Jun
17–19
Content Tokyo 2024https://www.content-tokyo.jp/ja-jp.html
View all events →

Top Sources

  1. 1.wTVision163
  2. 2.MSN150
  3. 3.Calendly86
  4. 4.Advanced Television63
  5. 5.Sports Video Group62
  6. 6.Cord Cutters News40
  7. 7.TV Technology39
  8. 8.AOL34
Full leaderboards →

Newest

about 18 hours ago
Pro AVL Central: Blackmagic Debuts Fairlight Live, Boosts DaVinci Resolve 21 with AI and Photo Tools
about 18 hours ago
NewscastStudio: MXL Rapid Development Challenges Traditional Broadcast Standardization
about 18 hours ago
Smpte: SMPTE Media Technology Summit Returns to Pasadena November 2026
about 18 hours ago
Tech Times: Let's Encrypt charts Merkle Tree Certificate path for post-quantum TLS
about 18 hours ago
cvefeed.io: Netty Fixes Undetected Stream Truncation in Chunked OHTTP Messages
about 18 hours ago
Ietf: IETF Advances Network Protocol Drafts for Streaming Infrastructure
about 18 hours ago
Forasoft: Fora Soft Launches Monthly WebRTC & Real-time Video Engineering Report
about 18 hours ago
Atis: ATIS Outlines Practical Roadmap for North American 5G Standalone Deployment
about 18 hours ago
Youtube: 3GPP Advances 5G-Advanced with Release 19, Commences 6G Studies
about 18 hours ago
3gpp: 3GPP Release 6 Refines Radio Network Rules for Cell Handover, Measurement
about 18 hours ago
3gpp: 3GPP Details 20 Mobile Telecommunications Releases, Including Open Release 21
about 18 hours ago
Pro AVL Central: Matrox Launches IPMX-Ready Maevex MGX Series for 4K60 AV-over-IP
about 18 hours ago
GitHub: OpenMOSS Expands MOSS-TTS Family with Nano Model, Enhanced SoundEffects
about 18 hours ago
NewscastStudio: Media Exchange Layer (MXL) Complements ST 2110 for Software-Defined Production
about 18 hours ago
Penligent Security Blog – AI-Driven Hacking Tutorials, Exploit PoCs & Cybersecurity Research: HTTP/2 Bomb Vulnerability: Apache, Envoy, Nginx Face DoS Risk
about 18 hours ago
SamsungNewsroom: Samsung Galaxy S26 Series Introduces Cine LUT for Accessible Mobile Color Grading
about 18 hours ago
KORE1: Spotify Engineers: A Six-Profile Map for Strategic Hiring
about 18 hours ago
TV Tech: GatesAir Establishes Brazil Hub for DTV+ Rollout, Local Support
about 19 hours ago
Telecompaper: Technicolor Joins Pearl TV Initiative for Affordable ATSC 3.0 Converter Boxes
about 19 hours ago
law360: Generative AI, SEPs Drive IP Licensing Activity from May 22-June 4

Upcoming Events

Jun
8–11
NEM Dubrovnikhttps://neweumarket.com/dubrovnik/
Jun
11–12
Arctic 15https://arctic15.com/
Jun
13–19
InfoCommhttps://www.infocommshow.org/
Jun
16–19
Stream TV Show (formerly the Pay TV Show)https://www.streamtvshow.com/
Jun
17–19
Content Tokyo 2024https://www.content-tokyo.jp/ja-jp.html
View all events →

Top Sources

  1. 1.wTVision163
  2. 2.MSN150
  3. 3.Calendly86
  4. 4.Advanced Television63
  5. 5.Sports Video Group62
  6. 6.Cord Cutters News40
  7. 7.TV Technology39
  8. 8.AOL34
Full leaderboards →