Bug 2531085
| Summary: | CVE-2026-57161 asterisk: stack overflow handling Service-Route headers in a registration response [epel-all] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora EPEL | Reporter: | Guilherme de Almeida Suckevicz <gsuckevi> |
| Component: | asterisk | Assignee: | EPEL Packagers SIG <epel-packagers-sig> |
| Status: | CLOSED NOTABUG | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | epel10 | CC: | bennie.joubert, epel-packagers-sig, jsmith.fedora, lemenkov |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | {"flaws": ["09418bf5-eae8-4b71-ae97-aaab5642ee49"]} | ||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2026-09-11 19:57:09 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2528784 | ||
|
Description
Guilherme de Almeida Suckevicz
2026-09-09 17:26:23 UTC
Not applicable to Asterisk. This is a stack buffer overflow in update_service_route() in pjsua_acc.c. The upstream advisory states it affects applications that register using the PJSUA/PJSUA2 account API. Asterisk does not use PJSUA. It builds on the lower-level PJSIP API directly, and there are no references to the PJSUA account API anywhere in the Asterisk source tree. Fixed upstream in pjproject commit acc03b5. Same determination as the Fedora tracker, bug 2531084. Closing as NOTABUG per the analysis above — the flaw is in the PJSUA account API, which Asterisk does not use. As with the other pjproject CVEs in this batch, this is a reachability determination rather than the code being absent: pjsua_acc.c is still compiled into the bundled library. It would need revisiting if Asterisk adopted the PJSUA API. |