CVE-2025-54995
28.08.2025, 15:16
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17.Enginsight
| Vendor | Product | Version |
|---|---|---|
| sangoma | asterisk | 𝑥 < 18.26.4 |
| sangoma | certified_asterisk | 𝑥 < 18.9 |
| sangoma | certified_asterisk | 18.9:cert1 |
| sangoma | certified_asterisk | 18.9:cert1-rc1 |
| sangoma | certified_asterisk | 18.9:cert10 |
| sangoma | certified_asterisk | 18.9:cert11 |
| sangoma | certified_asterisk | 18.9:cert12 |
| sangoma | certified_asterisk | 18.9:cert13 |
| sangoma | certified_asterisk | 18.9:cert14 |
| sangoma | certified_asterisk | 18.9:cert15 |
| sangoma | certified_asterisk | 18.9:cert16 |
| sangoma | certified_asterisk | 18.9:cert2 |
| sangoma | certified_asterisk | 18.9:cert3 |
| sangoma | certified_asterisk | 18.9:cert4 |
| sangoma | certified_asterisk | 18.9:cert5 |
| sangoma | certified_asterisk | 18.9:cert6 |
| sangoma | certified_asterisk | 18.9:cert7 |
| sangoma | certified_asterisk | 18.9:cert8 |
| sangoma | certified_asterisk | 18.9:cert8-rc1 |
| sangoma | certified_asterisk | 18.9:cert8-rc2 |
| sangoma | certified_asterisk | 18.9:cert9 |
𝑥
= Vulnerable software versions
Debian Releases
References