CVE-2026-40613

Name
CVE-2026-40613
Description
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.10.0, the STUN/TURN attribute parsing functions in coturn perform unsafe pointer casts from uint8_t * to uint16_t * without alignment checks. When processing a crafted STUN message with odd-aligned attribute boundaries, this results in misaligned memory reads at ns_turn_msg.c. On ARM64 architectures (AArch64) with strict alignment enforcement, this causes a SIGBUS signal that immediately kills the turnserver process. An unauthenticated remote attacker can crash any ARM64 coturn deployment by sending a single crafted UDP packet. This vulnerability is fixed in 4.10.0.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security-advisories@github.com https://github.com/coturn/coturn/security/advisories/GHSA-j662-9wcj-mf36

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:coturn_project:coturn:*:*:*:*:*:*:*:* coturn >= None < 4.10.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
coturn edge-community 4.10.0-r0 wener <wenermail@gmail.com> fixed
coturn edge-community 4.9.0-r0 wener <wenermail@gmail.com> possibly vulnerable
coturn edge-community 4.7.0-r0 wener <wenermail@gmail.com> possibly vulnerable
coturn edge-community 4.6.3-r1 wener <wenermail@gmail.com> possibly vulnerable
coturn edge-community 4.6.3-r0 wener <wenermail@gmail.com> possibly vulnerable
coturn edge-community 4.6.2-r0 wener <wenermail@gmail.com> possibly vulnerable
coturn edge-community 4.5.2-r0 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
coturn edge-community 4.5.1.3-r0 None possibly vulnerable
coturn 3.23-community 4.10.0-r0 wener <wenermail@gmail.com> fixed
coturn 3.23-community 4.7.0-r0 wener <wenermail@gmail.com> possibly vulnerable