CVE-2021-26906
NixOS vulnerability analysis and mitigation

Overview

CVE-2021-26906 is a vulnerability discovered in Digium Asterisk's PJSIP channel driver, affecting versions through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, as well as Certified Asterisk through 16.8-cert5. The vulnerability was reported on December 4, 2020, by Mauri de Souza Meneguzzo from 3CPlus and was publicly disclosed on February 8, 2021 (Asterisk Advisory).

Technical details

The vulnerability exists in the res_pjsip_session.c component, specifically in the SDP negotiation process. The code responsible for negotiating SDP in SIP responses incorrectly assumes that SDP negotiation will always be successful. The issue occurs when a SIP response containing an SDP that cannot be negotiated is received, causing a subsequent SDP negotiation on the same call to trigger a crash. This vulnerability has been assigned a CVSS v3.1 Base Score of 5.9 (Medium) with vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

When exploited, this vulnerability can lead to a denial of service condition through a crash of the Asterisk system. The crash can be triggered under specific conditions involving SDP negotiation failures during call setup, particularly affecting outgoing calls from Asterisk to remote SIP servers (Asterisk Advisory).

Exploitability

The vulnerability can be triggered remotely without authentication, though it requires specific timing conditions to be met. The crash occurs when a race condition is triggered where a second SDP negotiation happens before the call termination due to an initial SDP negotiation failure. This can happen in several scenarios, including when the 'accept_multiple_sdp_answers' option is set to 'yes' or when using the default 'follow_early_media_fork' setting (Asterisk Advisory).

Mitigation and workarounds

The issue has been fixed in PJSIP by modifying the behavior of the pjmedia_sdp_neg_modify_local_offer2 function to properly check if SDP was successfully negotiated rather than assuming success. Fixed versions include Asterisk Open Source 13.38.2, 16.16.1, 17.9.2, 18.2.1, and Certified Asterisk 16.8-cert6. Users are advised to upgrade to these patched versions (Asterisk Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84121CRITICAL9.6
  • NixOS logoNixOS
  • firefox-esr
NoYesSep 01, 2026
CVE-2026-84123HIGH8.8
  • NixOS logoNixOS
  • thunderbird
NoYesSep 01, 2026
CVE-2026-84125MEDIUM5.4
  • NixOS logoNixOS
  • firefox
NoYesSep 01, 2026
CVE-2026-84124MEDIUM5.4
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesSep 01, 2026
CVE-2026-84122MEDIUM5.4
  • NixOS logoNixOS
  • firefox-esr
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management