CVE-2026-90558

Summary

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute arbitrary code during packet parsing and rendering.

Affected Software

VendorProductVersion RangeStatus
irontecsngrep0 <= 1.8.4affected

Weaknesses

  • CWE-121: Stack-based Buffer Overflow

References