CVE-2026-41415: Pjsip Pj Str Slen Underflow On Delimiter Strip
A pj_str_t-style length field is decremented by 2 after only checking the first byte (typically to strip a pair of delimiters such as '<' '>') with no prior verification that slen >= 2. If the string is shorter than the assumed delimiter pair, slen underflows. Because pj_str_t.slen (pj_ssize_t, signed) is implicitly converted to the unsigned pj_size_t accept
greprules fetch cve-2026-41415-pjsip-pj-str-slen-underflow-on-delimiter-strip --engine opengrepDescription
A pj_str_t-style length field is decremented by 2 after only checking the first byte (typically to strip a pair of delimiters such as '<' '>') with no prior verification that slen >= 2. If the string is shorter than the assumed delimiter pair, slen underflows. Because pj_str_t.slen (pj_ssize_t, signed) is implicitly converted to the unsigned pj_size_t accept
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.