SB2026092384 - Fedora 45 update for asterisk



SB2026092384 - Fedora 45 update for asterisk

Published: September 23, 2026

Security Bulletin ID SB2026092384
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper validation of certificate with host mismatch (CVE-ID: CVE-2026-84975)

CWE-ID: CWE-297 - Improper Validation of Certificate with Host Mismatch

CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to impersonate the target server and disclose sensitive information.

The vulnerability exists due to improper validation of certificate with host mismatch in the TLS server identity verification logic in the OpenSSL and GnuTLS backends when processing certificates with a DNS SubjectAltName containing an embedded NUL byte. A remote attacker can present a trusted certificate with a crafted embedded-NUL DNS SubjectAltName to impersonate the target server and disclose sensitive information.

Only applications using the PJSIP TLS or SIPS transport with server verification enabled are vulnerable, and mbedTLS-based deployments are not affected.


Remediation

Install update from vendor's website.