THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jwjp-4649-v8jp (high) — SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing

[GHSA] GHSA-jwjp-4649-v8jp (high) — SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing

medgithub_advisoriesPublished 2026-08-12

GHSA-jwjp-4649-v8jp Severity: high CVE: None

SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing

## Summary `SctpSackChunk.ParseChunk` reads the `numGapAckBlocks` and `numDuplicateTSNs` fields (each up to 65535) directly from an attacker-controlled SCTP SACK chunk and loops that many times reading 4 bytes per iteration, with no validation of the counts ag

Original source: https://github.com/advisories/GHSA-jwjp-4649-v8jp