CVE-2025-54995

Source
https://cve.org/CVERecord?id=CVE-2025-54995
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54995.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-54995
Aliases
  • GHSA-557q-795j-wfx2
Downstream
Published
2025-08-28T15:08:04.468Z
Modified
2026-08-12T15:14:04.930284Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Asterisk remotely exploitable leak of RTP UDP ports and internal resources
Details

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17.

Database specific
{
    "cwe_ids": [
        "CWE-1286",
        "CWE-400"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54995.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/asterisk/asterisk

Affected ranges

Type
GIT
Repo
https://github.com/asterisk/asterisk
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1-rc1:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert10:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert11:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert12:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert13:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert14:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert15:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert16:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert2:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert3:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert4:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert5:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert6:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert7:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc1:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc2:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:certified_asterisk:18.9:cert9:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "18.26.4"
        },
        {
            "fixed": "18.9"
        },
        {
            "introduced": "18.9-cert1"
        },
        {
            "last_affected": "18.9-cert1"
        },
        {
            "introduced": "18.9-cert1\\-rc1"
        },
        {
            "last_affected": "18.9-cert1\\-rc1"
        },
        {
            "introduced": "18.9-cert10"
        },
        {
            "last_affected": "18.9-cert10"
        },
        {
            "introduced": "18.9-cert11"
        },
        {
            "last_affected": "18.9-cert11"
        },
        {
            "introduced": "18.9-cert12"
        },
        {
            "last_affected": "18.9-cert12"
        },
        {
            "introduced": "18.9-cert13"
        },
        {
            "last_affected": "18.9-cert13"
        },
        {
            "introduced": "18.9-cert14"
        },
        {
            "last_affected": "18.9-cert14"
        },
        {
            "introduced": "18.9-cert15"
        },
        {
            "last_affected": "18.9-cert15"
        },
        {
            "introduced": "18.9-cert16"
        },
        {
            "last_affected": "18.9-cert16"
        },
        {
            "introduced": "18.9-cert2"
        },
        {
            "last_affected": "18.9-cert2"
        },
        {
            "introduced": "18.9-cert3"
        },
        {
            "last_affected": "18.9-cert3"
        },
        {
            "introduced": "18.9-cert4"
        },
        {
            "last_affected": "18.9-cert4"
        },
        {
            "introduced": "18.9-cert5"
        },
        {
            "last_affected": "18.9-cert5"
        },
        {
            "introduced": "18.9-cert6"
        },
        {
            "last_affected": "18.9-cert6"
        },
        {
            "introduced": "18.9-cert7"
        },
        {
            "last_affected": "18.9-cert7"
        },
        {
            "introduced": "18.9-cert8"
        },
        {
            "last_affected": "18.9-cert8"
        },
        {
            "introduced": "18.9-cert8\\-rc1"
        },
        {
            "last_affected": "18.9-cert8\\-rc1"
        },
        {
            "introduced": "18.9-cert8\\-rc2"
        },
        {
            "last_affected": "18.9-cert8\\-rc2"
        },
        {
            "introduced": "18.9-cert9"
        },
        {
            "last_affected": "18.9-cert9"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

18.*
18.17.0
18.17.0-rc1
18.17.1
18.18.0
18.18.0-rc1
18.18.1
18.19.0
18.19.0-rc1
18.19.0-rc2
18.20.0
18.20.0-rc1
18.20.1
18.20.2
18.21.0
18.21.0-rc1
18.21.0-rc2
18.22.0
18.22.0-rc1
18.22.0-rc2
18.23.0
18.23.0-rc1
18.23.1
18.24.0
18.24.0-rc1
18.24.1
18.24.2
18.24.3
18.25.0
18.25.0-rc1
18.25.0-rc2
18.26.0
18.26.0-rc1
18.26.1
18.26.2
18.26.3
18.9-cert1
18.9-cert10
18.9-cert11
18.9-cert12
18.9-cert13
18.9-cert14
18.9-cert15
18.9-cert16
18.9-cert1\-rc1
18.9-cert2
18.9-cert3
18.9-cert4
18.9-cert5
18.9-cert6
18.9-cert7
18.9-cert8
18.9-cert8\-rc1
18.9-cert8\-rc2
18.9-cert9
18.9.0-rc1
certified-18.*
certified-18.9-cert4
certified/18.*
certified/18.9-cert1
certified/18.9-cert2
certified/18.9-cert3
certified/18.9-cert4

Database specific

vanir_signatures_modified
"2026-08-12T15:14:04Z"
vanir_signatures
[
    {
        "id": "CVE-2025-54995-2f1c4562",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 1167.0,
            "function_hash": "145729777291115066216022018484112944860"
        },
        "source": "https://github.com/asterisk/asterisk/commit/0278f5bde14565c6838a6ec39bc21aee0cde56a9",
        "target": {
            "function": "pubsub_on_rx_refresh",
            "file": "res/res_pjsip_pubsub.c"
        }
    },
    {
        "id": "CVE-2025-54995-e7c2a00b",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 1215.0,
            "function_hash": "1500228987729815806424505684135433108"
        },
        "source": "https://github.com/asterisk/asterisk/commit/0278f5bde14565c6838a6ec39bc21aee0cde56a9",
        "target": {
            "function": "pubsub_on_evsub_state",
            "file": "res/res_pjsip_pubsub.c"
        }
    },
    {
        "id": "CVE-2025-54995-f7f7010a",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "297510067891725616302845623085158975544",
                "250062173122371167318651197639747041308",
                "294282854021332123694277308472979605225",
                "256550182049634878866420822206969356090",
                "48382631181779299050216574143685781550",
                "228212395942411753224535974016201003094",
                "86537656281638066729933881214830946079",
                "234559451727773472899046125808966550479",
                "321022540406287444392252904183271704258",
                "200953372557231781351186621932190099942",
                "319928782702755579301850254044336661280",
                "239922295079061409235770160265141439758",
                "278835645538617191712436862699065919731",
                "112465623135014602759404101573223018704",
                "277880951842078683583522670114109146065",
                "328149496651402991540212483891784557446",
                "223920227085934917749575098771847348749",
                "296068571506787089153691913523076113384",
                "95000420862198613659443033735509728752",
                "267594731889626633109825055389375142453",
                "183338978175085201218854140117132707324",
                "40576978401693180739221118840362911832",
                "75911315733925852292865031594096617802",
                "134014908982244310257959863284153195534",
                "66931776776088085353212103356268753611",
                "111431022383983195071844155322627239335",
                "61170264101247519359865831964556360621",
                "115228049233451047479664707436012438444",
                "25083802127741790729287077366087620126",
                "80998830663413645758383323612921690363",
                "77169600801713797954247965353866663606",
                "290325069720227737068133882831346511034",
                "226800969897125555220116742715028199388"
            ]
        },
        "source": "https://github.com/asterisk/asterisk/commit/0278f5bde14565c6838a6ec39bc21aee0cde56a9",
        "target": {
            "file": "res/res_pjsip_pubsub.c"
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54995.json"