Bug#1086030: asterisk: TURN support ist broken: DTLS packet from [::1]:xxxx dropped. Source not in ICE active candidate list.

David Gunzinger david at smoca.ch
Fri Oct 25 10:31:23 BST 2024


Package: asterisk
Version: 1:16.28.0~dfsg-0+deb11u4.1
Severity: important
Tags: patch

Dear Maintainer,

Asterisk fails to route over a TURN server. When setting core set debug category rtp:3 for ICE, the following error appears:
DTLS packet from [::1]:12868 dropped. Source not in ICE active candidate list.

This error stems from the Debian patch debian/patches/CVE-2023-49786.patch.
Building the package without this patch allows TURN functionality to work properly.

Upstream addressed this issue with an additional patch, available in commit 8c3ececb12d82ee5d63adad6b9f9e79ad239e803.
Cherry-picking and applying this patch to the source package resolves the problem.

Best Regards


-- System Information:
Debian Release: 11.11
  APT prefers oldstable-updates
  APT policy: (500, 'oldstable-updates'), (500, 'oldstable-security'), (500, 'oldstable')
Architecture: arm64 (aarch64)
Foreign Architectures: armhf

Kernel: Linux 6.1.21-v8+ (SMP w/4 CPU threads; PREEMPT)
Kernel taint flags: TAINT_CRAP
Locale: LANG=en_GB.UTF-8, LC_CTYPE=UTF-8 (charmap=locale: Cannot set LC_CTYPE to default locale: No such file or directory
locale: Cannot set LC_MESSAGES to default locale: No such file or directory
locale: Cannot set LC_ALL to default locale: No such file or directory
ANSI_X3.4-1968) (ignored: LC_ALL set to en_US.UTF-8), LANGUAGE=en_GB.UTF-8
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages asterisk depends on:
ii  adduser                  3.118+deb11u1
ii  asterisk-config          1:16.28.0~dfsg-0+deb11u4.1
ii  asterisk-core-sounds-en  1.6.1-1
ii  asterisk-modules         1:16.28.0~dfsg-0+deb11u4.1
ii  libc6                    2.31-13+rpt2+rpi1+deb11u11
ii  libcap2                  1:2.44-1
ii  libcrypt1                1:4.4.18-4
ii  libedit2                 3.1-20191231-2+b1
ii  libgcc-s1                10.2.1-6
ii  libjansson4              2.13.1-1.1
ii  libpopt0                 1.18-2
ii  libsqlite3-0             3.34.1-3+deb11u1
ii  libssl1.1                1.1.1w-0+deb11u1+rpt1
ii  libsystemd0              247.3-7+deb11u6
ii  liburiparser1            0.9.4+dfsg-1+deb11u1
ii  libuuid1                 2.36.1-8+deb11u2
ii  libxml2                  2.9.10+dfsg-6.7+deb11u5
ii  libxslt1.1               1.1.34-4+deb11u1
ii  lsb-base                 11.1.0

Versions of packages asterisk recommends:
ii  asterisk-moh-opsound-gsm                       2.03-1.1
ii  asterisk-voicemail [asterisk-voicemail-storag  1:16.28.0~dfsg-0+deb11u4
ii  sox                                            14.4.2+git20190427-2+deb11u2

Versions of packages asterisk suggests:
pn  asterisk-dahdi   <none>
pn  asterisk-dev     <none>
pn  asterisk-doc     <none>
pn  asterisk-ooh323  <none>
pn  asterisk-opus    <none>
pn  asterisk-vpb     <none>

-- debconf information excluded



More information about the Pkg-voip-maintainers mailing list