Out-of-bounds write in Asterisk Open Source and Certified Asterisk - CVE-2026-57199
Published: June 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to corrupt memory or cause a denial of service.
The vulnerability exists due to out-of-bounds write in app_sms when processing externally controlled SMS lengths. A remote attacker can supply crafted SMS length values to corrupt memory or cause a denial of service.
The issue is exposed only when the SMS dialplan application is explicitly used for routing calls to or from analog devices.
Affected software
Certified Asterisk
How to mitigate CVE-2026-57199
Certified Asterisk - addressed in versions 20.7-cert11, 22.8-cert3