{"id":"CVE-2025-54995","summary":"Asterisk remotely exploitable leak of RTP UDP ports and internal resources","details":"Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17.","aliases":["GHSA-557q-795j-wfx2"],"modified":"2026-08-12T15:14:04.930284Z","published":"2025-08-28T15:08:04.468Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-1286","CWE-400"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54995.json"},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00006.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54995.json"},{"type":"ADVISORY","url":"https://github.com/asterisk/asterisk/security/advisories/GHSA-557q-795j-wfx2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54995"},{"type":"FIX","url":"https://github.com/asterisk/asterisk/commit/0278f5bde14565c6838a6ec39bc21aee0cde56a9"},{"type":"FIX","url":"https://github.com/asterisk/asterisk/commit/eafcd7a451dcd007dddf324ac37dd55a4808338d"},{"type":"FIX","url":"https://github.com/asterisk/asterisk/pull/1405"},{"type":"FIX","url":"https://github.com/asterisk/asterisk/pull/1406"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/asterisk/asterisk","events":[{"introduced":"0"},{"fixed":"c576a69f1765fe9761940b564c39f04a786dfcf9"},{"fixed":"85601849c646709836f59007d04ca829ef0d5955"},{"introduced":"184c95dc01576b538c938b3b0fe2c8bf62102d33"},{"fixed":"0278f5bde14565c6838a6ec39bc21aee0cde56a9"},{"fixed":"eafcd7a451dcd007dddf324ac37dd55a4808338d"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING","REFERENCES"],"cpe":["cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:*:*:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1-rc1:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert10:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert11:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert12:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert13:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert14:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert15:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert16:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert2:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert3:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert4:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert5:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert6:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert7:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc1:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc2:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert9:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"18.26.4"},{"fixed":"18.9"},{"introduced":"18.9-cert1"},{"last_affected":"18.9-cert1"},{"introduced":"18.9-cert1\\-rc1"},{"last_affected":"18.9-cert1\\-rc1"},{"introduced":"18.9-cert10"},{"last_affected":"18.9-cert10"},{"introduced":"18.9-cert11"},{"last_affected":"18.9-cert11"},{"introduced":"18.9-cert12"},{"last_affected":"18.9-cert12"},{"introduced":"18.9-cert13"},{"last_affected":"18.9-cert13"},{"introduced":"18.9-cert14"},{"last_affected":"18.9-cert14"},{"introduced":"18.9-cert15"},{"last_affected":"18.9-cert15"},{"introduced":"18.9-cert16"},{"last_affected":"18.9-cert16"},{"introduced":"18.9-cert2"},{"last_affected":"18.9-cert2"},{"introduced":"18.9-cert3"},{"last_affected":"18.9-cert3"},{"introduced":"18.9-cert4"},{"last_affected":"18.9-cert4"},{"introduced":"18.9-cert5"},{"last_affected":"18.9-cert5"},{"introduced":"18.9-cert6"},{"last_affected":"18.9-cert6"},{"introduced":"18.9-cert7"},{"last_affected":"18.9-cert7"},{"introduced":"18.9-cert8"},{"last_affected":"18.9-cert8"},{"introduced":"18.9-cert8\\-rc1"},{"last_affected":"18.9-cert8\\-rc1"},{"introduced":"18.9-cert8\\-rc2"},{"last_affected":"18.9-cert8\\-rc2"},{"introduced":"18.9-cert9"},{"last_affected":"18.9-cert9"}]}}],"versions":["18.9-cert1","18.9-cert10","18.9-cert11","18.9-cert12","18.9-cert13","18.9-cert14","18.9-cert15","18.9-cert16","18.9-cert1\\-rc1","18.9-cert2","18.9-cert3","18.9-cert4","18.9-cert5","18.9-cert6","18.9-cert7","18.9-cert8","18.9-cert8\\-rc1","18.9-cert8\\-rc2","18.9-cert9","18.26.3","18.26.2","18.26.1","18.26.0","18.26.0-rc1","18.25.0","18.25.0-rc2","18.25.0-rc1","18.24.3","18.24.2","18.24.1","18.24.0","18.24.0-rc1","18.23.1","18.23.0","18.23.0-rc1","18.22.0","18.22.0-rc2","18.22.0-rc1","18.21.0","18.21.0-rc2","18.21.0-rc1","18.20.2","18.20.1","18.20.0","18.20.0-rc1","18.19.0","18.19.0-rc2","18.19.0-rc1","18.18.1","certified/18.9-cert4","certified-18.9-cert4","18.18.0","18.18.0-rc1","18.17.1","18.17.0","18.17.0-rc1","certified/18.9-cert3","certified/18.9-cert2","certified/18.9-cert1","18.9.0-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54995.json","vanir_signatures_modified":"2026-08-12T15:14:04Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/asterisk/asterisk/commit/0278f5bde14565c6838a6ec39bc21aee0cde56a9","target":{"file":"res/res_pjsip_pubsub.c","function":"pubsub_on_rx_refresh"},"deprecated":false,"digest":{"function_hash":"145729777291115066216022018484112944860","length":1167},"id":"CVE-2025-54995-2f1c4562","signature_type":"Function"},{"source":"https://github.com/asterisk/asterisk/commit/0278f5bde14565c6838a6ec39bc21aee0cde56a9","target":{"file":"res/res_pjsip_pubsub.c","function":"pubsub_on_evsub_state"},"deprecated":false,"digest":{"function_hash":"1500228987729815806424505684135433108","length":1215},"id":"CVE-2025-54995-e7c2a00b","signature_type":"Function","signature_version":"v1"},{"digest":{"line_hashes":["297510067891725616302845623085158975544","250062173122371167318651197639747041308","294282854021332123694277308472979605225","256550182049634878866420822206969356090","48382631181779299050216574143685781550","228212395942411753224535974016201003094","86537656281638066729933881214830946079","234559451727773472899046125808966550479","321022540406287444392252904183271704258","200953372557231781351186621932190099942","319928782702755579301850254044336661280","239922295079061409235770160265141439758","278835645538617191712436862699065919731","112465623135014602759404101573223018704","277880951842078683583522670114109146065","328149496651402991540212483891784557446","223920227085934917749575098771847348749","296068571506787089153691913523076113384","95000420862198613659443033735509728752","267594731889626633109825055389375142453","183338978175085201218854140117132707324","40576978401693180739221118840362911832","75911315733925852292865031594096617802","134014908982244310257959863284153195534","66931776776088085353212103356268753611","111431022383983195071844155322627239335","61170264101247519359865831964556360621","115228049233451047479664707436012438444","25083802127741790729287077366087620126","80998830663413645758383323612921690363","77169600801713797954247965353866663606","290325069720227737068133882831346511034","226800969897125555220116742715028199388"],"threshold":0.9},"id":"CVE-2025-54995-f7f7010a","signature_type":"Line","signature_version":"v1","source":"https://github.com/asterisk/asterisk/commit/0278f5bde14565c6838a6ec39bc21aee0cde56a9","target":{"file":"res/res_pjsip_pubsub.c"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}