CVE-2021-26717: High severity asterisk vulnerability
An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. When re-negotiating for T.38, if the initial remote response was delayed just enough, Asterisk would send both audio and T.38 in the SDP. If this happened, and the remote responded with a declined T.38 stream, then Asterisk would crash.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26717?
The severity of CVE-2021-26717 is high with a severity value of 7.5.
How does CVE-2021-26717 affect Sangoma Asterisk?
CVE-2021-26717 affects Sangoma Asterisk versions 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1, as well as Certified Asterisk versions before 16.8-cert6.
What is the impact of CVE-2021-26717?
The impact of CVE-2021-26717 is that when re-negotiating for T.38, if the initial remote response is delayed just enough, Asterisk may send both audio and T.38 in the SDP.
How do I check if my Sangoma Asterisk installation is affected by CVE-2021-26717?
To check if your Sangoma Asterisk installation is affected, verify the version number and compare it to the affected versions mentioned in the advisory.
How can I mitigate the vulnerability identified in CVE-2021-26717?
To mitigate the vulnerability, upgrade your Sangoma Asterisk installation to version 16.16.1, 17.9.2, 18.2.1, or a later version.