Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17.
{
"cwe_ids": [
"CWE-1286",
"CWE-400"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54995.json",
"cna_assigner": "GitHub_M"
}{
"cpe": [
"cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:*:*:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1-rc1:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert10:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert11:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert12:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert13:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert14:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert15:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert16:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert2:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert3:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert4:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert5:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert6:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert7:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc1:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc2:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert9:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "18.26.4"
},
{
"fixed": "18.9"
},
{
"introduced": "18.9-cert1"
},
{
"last_affected": "18.9-cert1"
},
{
"introduced": "18.9-cert1\\-rc1"
},
{
"last_affected": "18.9-cert1\\-rc1"
},
{
"introduced": "18.9-cert10"
},
{
"last_affected": "18.9-cert10"
},
{
"introduced": "18.9-cert11"
},
{
"last_affected": "18.9-cert11"
},
{
"introduced": "18.9-cert12"
},
{
"last_affected": "18.9-cert12"
},
{
"introduced": "18.9-cert13"
},
{
"last_affected": "18.9-cert13"
},
{
"introduced": "18.9-cert14"
},
{
"last_affected": "18.9-cert14"
},
{
"introduced": "18.9-cert15"
},
{
"last_affected": "18.9-cert15"
},
{
"introduced": "18.9-cert16"
},
{
"last_affected": "18.9-cert16"
},
{
"introduced": "18.9-cert2"
},
{
"last_affected": "18.9-cert2"
},
{
"introduced": "18.9-cert3"
},
{
"last_affected": "18.9-cert3"
},
{
"introduced": "18.9-cert4"
},
{
"last_affected": "18.9-cert4"
},
{
"introduced": "18.9-cert5"
},
{
"last_affected": "18.9-cert5"
},
{
"introduced": "18.9-cert6"
},
{
"last_affected": "18.9-cert6"
},
{
"introduced": "18.9-cert7"
},
{
"last_affected": "18.9-cert7"
},
{
"introduced": "18.9-cert8"
},
{
"last_affected": "18.9-cert8"
},
{
"introduced": "18.9-cert8\\-rc1"
},
{
"last_affected": "18.9-cert8\\-rc1"
},
{
"introduced": "18.9-cert8\\-rc2"
},
{
"last_affected": "18.9-cert8\\-rc2"
},
{
"introduced": "18.9-cert9"
},
{
"last_affected": "18.9-cert9"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING",
"REFERENCES"
]
}
"2026-08-12T15:14:04Z"
[
{
"id": "CVE-2025-54995-2f1c4562",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 1167.0,
"function_hash": "145729777291115066216022018484112944860"
},
"source": "https://github.com/asterisk/asterisk/commit/0278f5bde14565c6838a6ec39bc21aee0cde56a9",
"target": {
"function": "pubsub_on_rx_refresh",
"file": "res/res_pjsip_pubsub.c"
}
},
{
"id": "CVE-2025-54995-e7c2a00b",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 1215.0,
"function_hash": "1500228987729815806424505684135433108"
},
"source": "https://github.com/asterisk/asterisk/commit/0278f5bde14565c6838a6ec39bc21aee0cde56a9",
"target": {
"function": "pubsub_on_evsub_state",
"file": "res/res_pjsip_pubsub.c"
}
},
{
"id": "CVE-2025-54995-f7f7010a",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"297510067891725616302845623085158975544",
"250062173122371167318651197639747041308",
"294282854021332123694277308472979605225",
"256550182049634878866420822206969356090",
"48382631181779299050216574143685781550",
"228212395942411753224535974016201003094",
"86537656281638066729933881214830946079",
"234559451727773472899046125808966550479",
"321022540406287444392252904183271704258",
"200953372557231781351186621932190099942",
"319928782702755579301850254044336661280",
"239922295079061409235770160265141439758",
"278835645538617191712436862699065919731",
"112465623135014602759404101573223018704",
"277880951842078683583522670114109146065",
"328149496651402991540212483891784557446",
"223920227085934917749575098771847348749",
"296068571506787089153691913523076113384",
"95000420862198613659443033735509728752",
"267594731889626633109825055389375142453",
"183338978175085201218854140117132707324",
"40576978401693180739221118840362911832",
"75911315733925852292865031594096617802",
"134014908982244310257959863284153195534",
"66931776776088085353212103356268753611",
"111431022383983195071844155322627239335",
"61170264101247519359865831964556360621",
"115228049233451047479664707436012438444",
"25083802127741790729287077366087620126",
"80998830663413645758383323612921690363",
"77169600801713797954247965353866663606",
"290325069720227737068133882831346511034",
"226800969897125555220116742715028199388"
]
},
"source": "https://github.com/asterisk/asterisk/commit/0278f5bde14565c6838a6ec39bc21aee0cde56a9",
"target": {
"file": "res/res_pjsip_pubsub.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54995.json"