Alerts This Week
Warning Icon 1 1,489
Alerts This Week
Warning Icon 1 1,489

Fedora 42 Opensips Critical SQL Injection Patch for CVE-2026-25554 Advisory

fedora
Calendar Grey March 6, 2026
Dist Fedora Esm H88
Critical update for Opensips in Fedora 42 addresses authentication bypass. Immediate action recommended for system security.
Fix CVE-2026-25554

Summary

OpenSIPS or Open SIP Server is a very fast and flexible SIP (RFC3261)

proxy server. Written entirely in C, opensips can handle thousands calls

per second even on low-budget hardware. A C Shell like scripting language

provides full control over the server's behaviour. It's modular

architecture allows only required functionality to be loaded.

Currently the following modules are available: digest authentication,

CPL scripts, instant messaging, MySQL and UNIXODBC support, a presence agent,

radius authentication, record routing, an SMS gateway, a jabber gateway, a

transaction and dialog module, OSP module, statistics support,

registrar and user location.

Update Information:

Fix CVE-2026-25554

Change Log

* Wed Feb 25 2026 Peter Lemenkov - 3.5.9-2 - Backpost CVE-2026-25554 fix

References


[ 1 ] Bug #2442706 - CVE-2026-25554 opensips: OpenSIPS: Authentication bypass due to SQL injection in JWT processing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2442706

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1a199d8524' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: opensips
Product: Fedora 42
Version: 3.5.9
Release: 2.fc42
Summary: Open Source SIP Server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here