Source: asterisk X-Debbugs-CC: [email protected] Severity: grave Tags: security
Hi, The following vulnerability was published for pjsip, which is bundled in asterisk. CVE-2026-84975[0]: | PJSIP is a free and open source multimedia communication library | written in C. In 2.17 and earlier, the OpenSSL and GnuTLS backends | in pjlib/src/pj/ssl_sock_ossl.c and pjlib/src/pj/ssl_sock_gtls.c | copy DNS SubjectAltName values with string functions that | recalculate their length and truncate an embedded NUL byte. With | server verification enabled through --tls-verify-server for the | PJSIP TLS/SIPS transport, a certificate containing a DNS | SubjectAltName formed from the target hostname prefix followed by an | embedded NUL and an attacker-controlled suffix can therefore be | accepted for the prefix hostname. An attacker who possesses such a | certificate from a trusted issuer and can intercept the connection | can impersonate the target server, complete the SIP session, and | receive REGISTER credentials. The mbedTLS backend is not affected | because it preserves the explicit string length. No fixed version is | available as of this review. https://github.com/pjsip/pjproject/security/advisories/GHSA-382p-87mh-r3q8 Fixed by: https://github.com/pjsip/pjproject/commit/43d3bd77bb6833eab4c493503b8d564a754ddfdd If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-84975 https://www.cve.org/CVERecord?id=CVE-2026-84975 Please adjust the affected versions in the BTS as needed.

