Out-of-bounds write in Asterisk Open Source and Certified Asterisk - CVE-2026-57199

 

Out-of-bounds write in Asterisk Open Source and Certified Asterisk - CVE-2026-57199

Published: June 26, 2026


Vulnerability identifier: #VU135541
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-57199
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to corrupt memory or cause a denial of service.

The vulnerability exists due to out-of-bounds write in app_sms when processing externally controlled SMS lengths. A remote attacker can supply crafted SMS length values to corrupt memory or cause a denial of service.

The issue is exposed only when the SMS dialplan application is explicitly used for routing calls to or from analog devices.


Affected software

Asterisk Open Source
Certified Asterisk

How to mitigate CVE-2026-57199

Install security update from vendor's website.

Asterisk Open Source - addressed in versions 20.20.1, 21.12.3, 22.10.1, 23.4.1
Certified Asterisk - addressed in versions 20.7-cert11, 22.8-cert3

External References

Related Security Bulletins