Hi,
The following vulnerability was published for pjsip, which is
bundled in asterisk.
CVE-2026-84975[0]:
| PJSIP is a free and open source multimedia communication library
| written in C. In 2.17 and earlier, the OpenSSL and GnuTLS backends
| in pjlib/src/pj/ssl_sock_ossl.c and pjlib/src/pj/ssl_sock_gtls.c
| copy DNS SubjectAltName values with string functions that
| recalculate their length and truncate an embedded NUL byte. With
| server verification enabled through --tls-verify-server for the
| PJSIP TLS/SIPS transport, a certificate containing a DNS
| SubjectAltName formed from the target hostname prefix followed by an
| embedded NUL and an attacker-controlled suffix can therefore be
| accepted for the prefix hostname. An attacker who possesses such a
| certificate from a trusted issuer and can intercept the connection
| can impersonate the target server, complete the SIP session, and
| receive REGISTER credentials. The mbedTLS backend is not affected
| because it preserves the explicit string length. No fixed version is
| available as of this review.
https://github.com/pjsip/pjproject/security/advisories/GHSA-382p-87mh-r3q8
Fixed by: https://github.com/pjsip/pjproject/commit/43d3bd77bb6833eab4c493503b8d564a754ddfdd
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-84975
https://www.cve.org/CVERecord?id=CVE-2026-84975
Please adjust the affected versions in the BTS as needed.