CVE-2026-40613: fallo de gravedad alta en coturn
Coturn: Misaligned Memory Access in coturn STUN Attribute Parser (Remote DoS on ARM64)
Publicada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.5epss 1.5%
probabilidad de explotación
1.5%top 26% de las CVE
explotación observada
noninguna fuente lo reporta
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.10.0, the STUN/TURN attribute parsing functions in coturn perform unsafe pointer casts from uint8_t * to uint16_t * without alignment checks. When processing a crafted STUN message with odd-aligned attribute boundaries, this results in misaligned memory reads at ns_turn_msg.c. On ARM64 architectures (AArch64) with strict alignment enforcement, this causes a SIGBUS signal that immediately kills the turnserver process. An unauthenticated remote attacker can crash any ARM64 coturn deployment by sending a single crafted UDP packet. This vulnerability is fixed in 4.10.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Productos afectados
coturn · coturnCVEs relacionadas — coturn
En el mismo producto, de las más peligrosas a las menos.
CVE-2020-4067HIGHImproper Initialization in coturnEPSS 1.9%CVE-2020-26262HIGHLoopback bypass in CoturnEPSS 1.5%CVE-2026-53448HIGHCoturn: SQL Injection in HTTPS Admin Panel Delete OperationsEPSS 0.7%CVE-2026-43994HIGHCoturn: Stack buffer overflow in decode_oauth_token_gcm()EPSS 0.7%CVE-2026-73214HIGHcoturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exhaustion DoSEPSS 0.6%CVE-2026-73216MEDIUMcoturn: mobility disconnects bypass allocation quotas and exhaust relay capacityEPSS 0.6%