What is CVE-2026-71980?
Belledonne Communications bcg729 through version 1.1.2 has an out-of-bounds read vulnerability in the decodeSIDframe() function. An unauthenticated network-adjacent attacker can exploit this by sending a zero-length comfort-noise RTP payload, leading to a heap read beyond buffer boundaries. Affected users should update to the latest version of the library.
Azərbaycanca: Belledonne Communications bcg729 kitabxanasının 1.1.2 versiyasına qədər olan versiyalarında decodeSIDframe() funksiyasında "out-of-bounds read" zəifliyi aşkarlanıb. Bu, şəbəkəyə qoşulmuş autentifikasiya olunmamış hücumçulara sıfır uzunluqlu "comfort-noise RTP payload" göndərərək heap yaddaşda oxuma sərhədini aşmağa imkan verir. Təsirə məruz qalan istifadəçilər kitabxananı ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Which versions of the bcg729 library are affected by CVE-2026-71980?
Belledonne Communications bcg729 through version 1.1.2 is affected by this vulnerability.
Is authentication required to exploit CVE-2026-71980?
No, this vulnerability can be exploited by an unauthenticated network-adjacent attacker.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.