Numeric Range Comparison Without Minimum Check in Asterisk Open Source and Certified Asterisk - CVE-2026-57186
Published: June 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to numeric range comparison without minimum check in the chan_ooh323 Q.931 party-number parser when parsing malformed Q.931 elements in an OOH323 request. A remote attacker can send a specially crafted OOH323 request to cause a denial of service.
Only systems with the chan_ooh323 addon channel driver explicitly compiled and installed are vulnerable.
Affected software
Certified Asterisk
How to mitigate CVE-2026-57186
Certified Asterisk - update to 22.8-cert3