{"id":"CVE-2021-26906","details":"An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 16.8-cert5. An SDP negotiation vulnerability in PJSIP allows a remote server to potentially crash Asterisk by sending specific SIP responses that cause an SDP negotiation failure.","modified":"2026-02-11T14:27:14.078385Z","published":"2021-02-18T20:15:12.743Z","references":[{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/161477/Asterisk-Project-Security-Advisory-AST-2021-005.html"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2021/Feb/61"},{"type":"ADVISORY","url":"https://downloads.asterisk.org/pub/security/"},{"type":"ADVISORY","url":"https://downloads.asterisk.org/pub/security/AST-2021-005.html"},{"type":"ADVISORY","url":"https://issues.asterisk.org/jira/browse/ASTERISK-29196"},{"type":"REPORT","url":"https://issues.asterisk.org/jira/browse/ASTERISK-29196"},{"type":"FIX","url":"http://seclists.org/fulldisclosure/2021/Feb/61"},{"type":"FIX","url":"https://issues.asterisk.org/jira/browse/ASTERISK-29196"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2021/Feb/61"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/asterisk/asterisk","events":[{"introduced":"2c1bba3cbec008c8ce35c78a2c79f9f207ea58bc"},{"fixed":"332130c4389803a3c7e63cabf00daf5ac66a3068"},{"introduced":"5ffe12b6ef30cd503f85d75745fd8d9c2cfafe47"},{"fixed":"fdaf2d0689b7a8928a45019c9af14c53bcdfa6e3"},{"introduced":"85335355efb2d7914a1fe20ed31afcef15fd210c"},{"fixed":"fbaea22493a6061d4bdc87bddc0cb5971e5f71d9"},{"introduced":"a65908f83e2f17a3aca7eb39c8e06045aca02674"},{"fixed":"3cd8afbdf2c6dffe80c631a5336e21bb1827a5cd"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-26906.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}