{"id":"CVE-2025-57767","summary":"Asterisk can crash from a specifically malformed Authorization header in an incoming SIP request","details":"Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, and 22.5.2, if a SIP request is received with an Authorization header that contains a realm that wasn't in a previous 401 response's WWW-Authenticate header, or an Authorization header with an incorrect realm was received without a previous 401 response being sent, the get_authorization_header() function in res_pjsip_authenticator_digest will return a NULL. This wasn't being checked before attempting to get the digest algorithm from the header which causes a SEGV. This issue has been patched in versions 20.15.2, 21.10.2, and 22.5.2. There are no workarounds.","aliases":["GHSA-64qc-9x89-rx5j"],"modified":"2026-08-12T15:16:50.333161Z","published":"2025-08-28T15:33:00.087Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-253"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57767.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57767.json"},{"type":"ADVISORY","url":"https://github.com/asterisk/asterisk/security/advisories/GHSA-64qc-9x89-rx5j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-57767"},{"type":"FIX","url":"https://github.com/asterisk/asterisk/commit/02993717b08f899d4aca9888062f35dfb198584f"},{"type":"FIX","url":"https://github.com/asterisk/asterisk/pull/1407"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/asterisk/asterisk","events":[{"introduced":"0"},{"fixed":"f34af3980567b3616ecd49730408bb6dff792de9"},{"introduced":"12da95e53ff42287ad69d6d5922e06c3d62010ac"},{"fixed":"dc6416062db89287ad9b35f8f7780acd7146b0c6"},{"introduced":"8e4a09f71162ebc1e4bb2159dfc638aa2328047c"},{"fixed":"a4b54349a1bce79c06696305ca0b658f90477877"},{"fixed":"02993717b08f899d4aca9888062f35dfb198584f"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"20.15.2"},{"introduced":"21.0.0"},{"fixed":"21.10.2"},{"introduced":"22.0.0"},{"fixed":"22.5.2"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:*"}}],"versions":["20.15.0","20.15.0-rc3","20.15.0-rc1","20.15.0-rc2","20.15.1","20.14.0","21.10.0","21.10.0-rc3","21.10.0-rc1","21.10.0-rc2","21.10.1","21.9.0","22.5.0","22.5.0-rc3","22.5.0-rc1","22.5.0-rc2","22.5.1","22.4.0","22.4.0-rc1","21.9.0-rc1","20.14.0-rc1","22.3.0","21.8.0","20.13.0","22.3.0-rc1","21.8.0-rc1","20.13.0-rc1","22.2.0","21.7.0","20.12.0","22.2.0-rc2","21.7.0-rc2","20.12.0-rc2","22.2.0-rc1","21.7.0-rc1","20.12.0-rc1","22.1.1","21.6.1","20.11.1","22.1.0","21.6.0","20.11.0","22.1.0-rc1","21.6.0-rc1","20.11.0-rc1","22.0.0","21.5.0","20.10.0","20.10.0-rc2","21.5.0-rc2","21.5.0-rc1","20.10.0-rc1","21.4.3","20.9.3","21.4.2","20.9.2","21.4.1","20.9.1","20.9.0","21.4.0","21.4.0-rc1","20.9.0-rc1","21.3.1","20.8.1","21.3.0","20.8.0","21.3.0-rc1","20.8.0-rc1","certified-20.7-cert1-pre1","20.7.0","21.2.0","21.2.0-rc2","20.7.0-rc2","20.7.0-rc1","21.2.0-rc1","21.1.0","20.6.0","21.1.0-rc2","20.6.0-rc2","21.1.0-rc1","20.6.0-rc1","21.0.2","20.5.2","20.5.1","21.0.1","21.0.0","20.5.0","20.5.0-rc1","20.4.0","20.4.0-rc2","20.4.0-rc1","20.3.1","20.3.0","20.3.0-rc1","20.2.1","20.2.0","20.2.0-rc1"],"database_specific":{"vanir_signatures":[{"source":"https://github.com/asterisk/asterisk/commit/02993717b08f899d4aca9888062f35dfb198584f","target":{"file":"res/res_pjsip_authenticator_digest.c","function":"digest_lookup"},"deprecated":false,"digest":{"length":2393,"function_hash":"107882573564604585624201498152436135581"},"id":"CVE-2025-57767-71141676","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["277113248831915314237292959927735528212","26076776454639219442901390736304469642","229953372221277453769434869868126404944","137481854344370599437213900924473762372","82755533326211727937228182954525794937","49066820799980664296549011749812836794","334763552888328235903640845191001292168","265295399912787821942055360511167746276","181835901875177897785136430575958951080","282180388400386255834846649031299083511","132830972370239002539433144018311031757","141064321184641834148639187512199981765","284648278444002065858453528195805135505","174685326093314722010253079827554637724","227229970931242580871204575113999963605","63124256552325911008131164803349470862","222521996826963428849393884234670607455","237519995051812834915892471091847100586"],"threshold":0.9},"id":"CVE-2025-57767-9675c8da","signature_type":"Line","signature_version":"v1","source":"https://github.com/asterisk/asterisk/commit/02993717b08f899d4aca9888062f35dfb198584f","target":{"file":"res/res_pjsip_authenticator_digest.c"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57767.json","vanir_signatures_modified":"2026-08-12T15:16:50Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}