Out-of-bounds write in Asterisk Open Source and Certified Asterisk - CVE-2026-57189
Published: June 26, 2026
Asterisk Open Source
Certified Asterisk
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code or cause a denial of service.
The vulnerability exists due to out-of-bounds write in T.140 RED generation handling when processing carefully crafted packets. A remote user can send carefully crafted packets to execute arbitrary code or cause a denial of service.
Only systems using the chan_sip channel driver with the textsupport option enabled are vulnerable.