CVE-2026-0160
TextRtpPayloadDecoderNode (Software/Library) · TextRtpPayloadDecoderNode
The DecodeT140 function in the TextRtpPayloadDecoderNode is vulnerable to memory corruption due to improper processing.
Executive summary
A high-severity memory corruption vulnerability in the TextRtpPayloadDecoderNode's DecodeT140 function poses a risk of unauthorized code execution.
Vulnerability
The vulnerability exists in the DecodeT140 function of the TextRtpPayloadDecoderNode component. It is triggered during the processing of T.140 text-over-RTP packets, where improper handling leads to memory corruption.
Business impact
Successful exploitation could allow an attacker to compromise the host system running the decoder, leading to unauthorized data access or service disruption. A CVSS score of 8.8 reflects the high risk, highlighting the need for immediate remediation to protect sensitive communication systems.
Remediation
Immediate Action: Update the affected software containing the TextRtpPayloadDecoderNode to the latest patch level.
Proactive Monitoring: Monitor logs for crashes or memory-related exceptions within the text decoding service.
Compensating Controls: Use network security controls to inspect and sanitize RTP traffic, specifically looking for anomalous T.140 payload structures.
Exploitation status
Public Exploit Available: false
Analyst recommendation
This vulnerability is critical for environments utilizing T.140 over RTP. Organizations should prioritize updating the software components associated with the TextRtpPayloadDecoderNode to eliminate this memory corruption risk and prevent potential exploitation.