CVE Vulnerabilities

CVE-2022-24763

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Mar 30, 2022 | Modified: Nov 04, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulnerability that affects PJSIP users that consume PJSIPs XML parsing in their apps. Users are advised to update. There are no known workarounds.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
PjsipPjsip2.5 (including)2.13 (excluding)
PjprojectUbuntubionic*
PjprojectUbuntutrusty*
PjprojectUbuntuxenial*
RingUbuntubionic*
RingUbuntuesm-apps/bionic*
RingUbuntuesm-apps/focal*
RingUbuntufocal*
RingUbuntuimpish*
RingUbuntutrusty*
RingUbuntuxenial*

References