CVE-2022-26651
NixOS vulnerability analysis and mitigation

Overview

An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL queries, which could result in broken SQL queries or potential SQL injection. This vulnerability was reported on January 5, 2022, and publicly disclosed on April 14, 2022, identified as CVE-2022-26651. The issue affects all versions of Asterisk Open Source 16.x, 18.x, 19.x, and Certified Asterisk 16.x, and was fixed in versions 16.25.2, 18.11.2, 19.3.2, and 16.8-cert14 (Asterisk Advisory).

Technical details

The vulnerability exists in the funcodbc module where some databases can use backslashes to escape certain characters, such as backticks. When input containing backslashes is provided to funcodbc, it may construct a broken SQL query, causing the query to fail. While not confirmed, there is potential for SQL injection that could allow database manipulation by an external party. The severity of this vulnerability is classified as Low (Asterisk Advisory).

Impact

If exploited, this vulnerability could lead to broken SQL queries and potential database manipulation through SQL injection. The impact is particularly relevant for systems using func_odbc with databases that utilize backslashes for character escaping (Asterisk Advisory).

Mitigation and workarounds

Two mitigation options are available: 1) Use the new SQLESCBACKSLASHES dialplan function added to the func_odbc module to escape backslashes when input may contain them and the database uses backslashes to escape backticks, or 2) Disable support for backslashes for escaping in the database if the underlying database supports this configuration change (Asterisk Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14330CRITICAL9.8
  • NixOSNixOS
  • rhel10::firefox-flatpak
NoYesDec 09, 2025
CVE-2025-14329HIGH8.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesDec 09, 2025
CVE-2025-14333HIGH8.1
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025
CVE-2025-14332HIGH7.3
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesDec 09, 2025
CVE-2025-14331MEDIUM6.5
  • NixOSNixOS
  • rhel10::thunderbird-flatpak
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management