Heap-based buffer overflow in Asterisk Open Source and Certified Asterisk - CVE-2026-57198
Published: June 26, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code or cause a denial of service.
The vulnerability exists due to heap-based buffer overflow in the T.140 RED handling in chan_sip when processing carefully crafted packets. A remote user can send specially crafted packets to execute arbitrary code or cause a denial of service.
Only systems using the chan_sip channel driver with the textsupport option enabled are vulnerable.
Affected software
Certified Asterisk
How to mitigate CVE-2026-57198
Certified Asterisk - addressed in versions 20.7-cert11, 22.8-cert3