Buffer Overflow Affecting asterisk package, versions <1:22.9.0+dfsg+~cs6.16.60671434-1


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.32% (25th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-ASTERISK-16134260
  • published23 Apr 2026
  • disclosed21 Nov 2025

Introduced: 21 Nov 2025

CVE-2025-65102  (opens in a new tab)
CWE-120  (opens in a new tab)

How to fix?

Upgrade Debian:unstable asterisk to version 1:22.9.0+dfsg+~cs6.16.60671434-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream asterisk package and not the asterisk package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

PJSIP is a free and open source multimedia communication library. Prior to version 2.16, Opus PLC may zero-fill the input frame as long as the decoder ptime, while the input frame length, which is based on stream ptime, may be less than that. This issue affects PJSIP users who use the Opus audio codec in receiving direction. The vulnerability can lead to unexpected application termination due to a memory overwrite. This issue has been patched in version 2.16.