Out-of-bounds write in Asterisk Open Source and Certified Asterisk - CVE-2026-57192
Published: June 26, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to out-of-bounds write in the Codec2 decoder when processing carefully crafted Codec2 audio packets during a call. A remote user can send crafted Codec2 audio packets to cause a denial of service.
The codec_codec2 module must be loaded, the codec2 codec must be configured on the attacked endpoint, and user authentication is required to establish a call using the codec.
Affected software
Certified Asterisk
How to mitigate CVE-2026-57192
Certified Asterisk - addressed in versions 20.7-cert11, 22.8-cert3