CVE-2026-104074

NameCVE-2026-104074
DescriptionCoturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents by sending a TURN Allocate request without credentials. Attackers can exploit the stun_init_error_response_common_str() function in src/client/ns_turn_msg.c, which fails to zero-initialize the avalue buffer before computing its length with strlen() and copying leaked stack bytes into the ERROR-CODE reason phrase, exposing pointer fragments that weaken ASLR and enable precise version fingerprinting.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
coturn (PTS)bookworm4.6.1-1vulnerable
trixie4.6.1-2vulnerable
sid4.18.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
coturnsource(unstable)4.12.0-1

Notes

https://github.com/coturn/coturn/pull/1878
Fixed by: https://github.com/coturn/coturn/commit/741b2983cc52f967dd08c438fd72a5f08f13ca27 (4.11.0)

Search for package or bug name: Reporting problems