Date: Thu, 5 Feb 2026 16:50:46 +0000
Subject: [PATCH] Update for 22.8.2
---
.version | 2 +-
CHANGES.html | 2 +-
CHANGES.md | 2 +-
ChangeLogs/ChangeLog-22.8.2.html | 103 ++++++++++++++++++++++++++
ChangeLogs/ChangeLog-22.8.2.md | 119 +++++++++++++++++++++++++++++++
README.html | 4 +-
README.md | 2 +-
7 files changed, 228 insertions(+), 6 deletions(-)
create mode 100644 ChangeLogs/ChangeLog-22.8.2.html
create mode 100644 ChangeLogs/ChangeLog-22.8.2.md
diff --git a/.version b/.version
index baa600584f..955174f9da 100644
--- a/.version
+++ b/.version
@@ -1 +1 @@
-22.8.1
+22.8.2
diff --git a/CHANGES.html b/CHANGES.html
index 03103a6b29..905be0926e 120000
--- a/CHANGES.html
+++ b/CHANGES.html
@@ -1 +1 @@
-ChangeLogs/ChangeLog-22.8.1.html
\ No newline at end of file
+ChangeLogs/ChangeLog-22.8.2.html
\ No newline at end of file
diff --git a/CHANGES.md b/CHANGES.md
index 2fb43aef03..6c73404570 120000
--- a/CHANGES.md
+++ b/CHANGES.md
@@ -1 +1 @@
-ChangeLogs/ChangeLog-22.8.1.md
\ No newline at end of file
+ChangeLogs/ChangeLog-22.8.2.md
\ No newline at end of file
diff --git a/ChangeLogs/ChangeLog-22.8.2.html b/ChangeLogs/ChangeLog-22.8.2.html
new file mode 100644
index 0000000000..7e16ef4d8a
--- /dev/null
+++ b/ChangeLogs/ChangeLog-22.8.2.html
@@ -0,0 +1,103 @@
+ChangeLog for asterisk-22.8.2
+Change Log for Release asterisk-22.8.2
+Links:
+
+Summary:
+
+- Commits: 4
+- Commit Authors: 2
+- Issues Resolved: 0
+- Security Advisories Resolved: 4
+- GHSA-85x7-54wr-vh42: Asterisk xml.c uses unsafe XML_PARSE_NOENT leading to potential XXE Injection
+- GHSA-rvch-3jmx-3jf3: ast_coredumper running as root sources ast_debug_tools.conf from /etc/asterisk; potentially leading to privilege escalation
+- GHSA-v6hp-wh3r-cwxh: The Asterisk embedded web server's /httpstatus page echos user supplied values(cookie and query string) without sanitization
+- GHSA-xpc6-x892-v83c: ast_coredumper runs as root, and writes gdb init file to world writeable folder; leading to potential privilege escalation
+
+User Notes:
+
+-
+
ast_coredumper: check ast_debug_tools.conf permissions
+ ast_debug_tools.conf must be owned by root and not be
+ writable by other users or groups to be used by ast_coredumper or
+ by ast_logescalator or ast_loggrabber when run as root.
+
+Upgrade Notes:
+
+-
+
http.c: Change httpstatus to default disabled and sanitize output.
+ To prevent possible security issues, the /httpstatus page
+ served by the internal web server is now disabled by default. To explicitly
+ enable it, set enable_status=yes in http.conf.
+
+Developer Notes:
+Commit Authors:
+
+- George Joseph: (2)
+- Mike Bradeen: (2)
+
+Issue and Commit Detail:
+Closed Issues:
+
+- !GHSA-85x7-54wr-vh42: Asterisk xml.c uses unsafe XML_PARSE_NOENT leading to potential XXE Injection
+- !GHSA-rvch-3jmx-3jf3: ast_coredumper running as root sources ast_debug_tools.conf from /etc/asterisk; potentially leading to privilege escalation
+- !GHSA-v6hp-wh3r-cwxh: The Asterisk embedded web server's /httpstatus page echos user supplied values(cookie and query string) without sanitization
+- !GHSA-xpc6-x892-v83c: ast_coredumper runs as root, and writes gdb init file to world writeable folder; leading to potential privilege escalation
+
+Commits By Author:
+
+-
+
George Joseph (2):
+
+-
+
Mike Bradeen (2):
+
+
+Commit List:
+
+- xml.c: Replace XML_PARSE_NOENT with XML_PARSE_NONET for xmlReadFile.
+- ast_coredumper: check ast_debug_tools.conf permissions
+- http.c: Change httpstatus to default disabled and sanitize output.
+- ast_coredumper: create gdbinit file with restrictive permissions
+
+Commit Details:
+xml.c: Replace XML_PARSE_NOENT with XML_PARSE_NONET for xmlReadFile.
+Author: George Joseph
+ Date: 2026-01-15
+The xmlReadFile XML_PARSE_NOENT flag, which allows parsing of external
+ entities, could allow a potential XXE injection attack. Replacing it with
+ XML_PARSE_NONET, which prevents network access, is safer.
+Resolves: #GHSA-85x7-54wr-vh42
+ast_coredumper: check ast_debug_tools.conf permissions
+Author: Mike Bradeen
+ Date: 2026-01-15
+Prevent ast_coredumper from using ast_debug_tools.conf files that are
+ not owned by root or are writable by other users or groups.
+Prevent ast_logescalator and ast_loggrabber from doing the same if
+ they are run as root.
+Resolves: #GHSA-rvch-3jmx-3jf3
+UserNote: ast_debug_tools.conf must be owned by root and not be
+ writable by other users or groups to be used by ast_coredumper or
+ by ast_logescalator or ast_loggrabber when run as root.
+http.c: Change httpstatus to default disabled and sanitize output.
+Author: George Joseph
+ Date: 2026-01-15
+To address potential security issues, the httpstatus page is now disabled
+ by default and the echoed query string and cookie output is html-escaped.
+Resolves: #GHSA-v6hp-wh3r-cwxh
+UpgradeNote: To prevent possible security issues, the /httpstatus page
+ served by the internal web server is now disabled by default. To explicitly
+ enable it, set enable_status=yes in http.conf.
+ast_coredumper: create gdbinit file with restrictive permissions
+Author: Mike Bradeen
+ Date: 2026-01-15
+Modify gdbinit to use the install command with explicit permissions (-m 600)
+ when creating the .ast_coredumper.gdbinit file. This ensures the file is
+ created with restricted permissions (readable/writable only by the owner)
+ to avoid potential privilege escalation.
+Resolves: #GHSA-xpc6-x892-v83c
+
diff --git a/ChangeLogs/ChangeLog-22.8.2.md b/ChangeLogs/ChangeLog-22.8.2.md
new file mode 100644
index 0000000000..793b692d16
--- /dev/null
+++ b/ChangeLogs/ChangeLog-22.8.2.md
@@ -0,0 +1,119 @@
+
+## Change Log for Release asterisk-22.8.2
+
+### Links:
+
+ - [Full ChangeLog](https://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-22.8.2.html)
+ - [GitHub Diff](https://github.com/asterisk/asterisk/compare/22.8.1...22.8.2)
+ - [Tarball](https://downloads.asterisk.org/pub/telephony/asterisk/asterisk-22.8.2.tar.gz)
+ - [Downloads](https://downloads.asterisk.org/pub/telephony/asterisk)
+
+### Summary:
+
+- Commits: 4
+- Commit Authors: 2
+- Issues Resolved: 0
+- Security Advisories Resolved: 4
+ - [GHSA-85x7-54wr-vh42](https://github.com/asterisk/asterisk/security/advisories/GHSA-85x7-54wr-vh42): Asterisk xml.c uses unsafe XML_PARSE_NOENT leading to potential XXE Injection
+ - [GHSA-rvch-3jmx-3jf3](https://github.com/asterisk/asterisk/security/advisories/GHSA-rvch-3jmx-3jf3): ast_coredumper running as root sources ast_debug_tools.conf from /etc/asterisk; potentially leading to privilege escalation
+ - [GHSA-v6hp-wh3r-cwxh](https://github.com/asterisk/asterisk/security/advisories/GHSA-v6hp-wh3r-cwxh): The Asterisk embedded web server's /httpstatus page echos user supplied values(cookie and query string) without sanitization
+ - [GHSA-xpc6-x892-v83c](https://github.com/asterisk/asterisk/security/advisories/GHSA-xpc6-x892-v83c): ast_coredumper runs as root, and writes gdb init file to world writeable folder; leading to potential privilege escalation
+
+### User Notes:
+
+- #### ast_coredumper: check ast_debug_tools.conf permissions
+ ast_debug_tools.conf must be owned by root and not be
+ writable by other users or groups to be used by ast_coredumper or
+ by ast_logescalator or ast_loggrabber when run as root.
+
+
+### Upgrade Notes:
+
+- #### http.c: Change httpstatus to default disabled and sanitize output.
+ To prevent possible security issues, the `/httpstatus` page
+ served by the internal web server is now disabled by default. To explicitly
+ enable it, set `enable_status=yes` in http.conf.
+
+
+### Developer Notes:
+
+
+### Commit Authors:
+
+- George Joseph: (2)
+- Mike Bradeen: (2)
+
+## Issue and Commit Detail:
+
+### Closed Issues:
+
+ - !GHSA-85x7-54wr-vh42: Asterisk xml.c uses unsafe XML_PARSE_NOENT leading to potential XXE Injection
+ - !GHSA-rvch-3jmx-3jf3: ast_coredumper running as root sources ast_debug_tools.conf from /etc/asterisk; potentially leading to privilege escalation
+ - !GHSA-v6hp-wh3r-cwxh: The Asterisk embedded web server's /httpstatus page echos user supplied values(cookie and query string) without sanitization
+ - !GHSA-xpc6-x892-v83c: ast_coredumper runs as root, and writes gdb init file to world writeable folder; leading to potential privilege escalation
+
+### Commits By Author:
+
+- #### George Joseph (2):
+
+- #### Mike Bradeen (2):
+
+### Commit List:
+
+- xml.c: Replace XML_PARSE_NOENT with XML_PARSE_NONET for xmlReadFile.
+- ast_coredumper: check ast_debug_tools.conf permissions
+- http.c: Change httpstatus to default disabled and sanitize output.
+- ast_coredumper: create gdbinit file with restrictive permissions
+
+### Commit Details:
+
+#### xml.c: Replace XML_PARSE_NOENT with XML_PARSE_NONET for xmlReadFile.
+ Author: George Joseph
+ Date: 2026-01-15
+
+ The xmlReadFile XML_PARSE_NOENT flag, which allows parsing of external
+ entities, could allow a potential XXE injection attack. Replacing it with
+ XML_PARSE_NONET, which prevents network access, is safer.
+
+ Resolves: #GHSA-85x7-54wr-vh42
+
+#### ast_coredumper: check ast_debug_tools.conf permissions
+ Author: Mike Bradeen
+ Date: 2026-01-15
+
+ Prevent ast_coredumper from using ast_debug_tools.conf files that are
+ not owned by root or are writable by other users or groups.
+
+ Prevent ast_logescalator and ast_loggrabber from doing the same if
+ they are run as root.
+
+ Resolves: #GHSA-rvch-3jmx-3jf3
+
+ UserNote: ast_debug_tools.conf must be owned by root and not be
+ writable by other users or groups to be used by ast_coredumper or
+ by ast_logescalator or ast_loggrabber when run as root.
+
+#### http.c: Change httpstatus to default disabled and sanitize output.
+ Author: George Joseph
+ Date: 2026-01-15
+
+ To address potential security issues, the httpstatus page is now disabled
+ by default and the echoed query string and cookie output is html-escaped.
+
+ Resolves: #GHSA-v6hp-wh3r-cwxh
+
+ UpgradeNote: To prevent possible security issues, the `/httpstatus` page
+ served by the internal web server is now disabled by default. To explicitly
+ enable it, set `enable_status=yes` in http.conf.
+
+#### ast_coredumper: create gdbinit file with restrictive permissions
+ Author: Mike Bradeen
+ Date: 2026-01-15
+
+ Modify gdbinit to use the install command with explicit permissions (-m 600)
+ when creating the .ast_coredumper.gdbinit file. This ensures the file is
+ created with restricted permissions (readable/writable only by the owner)
+ to avoid potential privilege escalation.
+
+ Resolves: #GHSA-xpc6-x892-v83c
+
diff --git a/README.html b/README.html
index a33acc7380..438e828d1f 100644
--- a/README.html
+++ b/README.html
@@ -1,4 +1,4 @@
-Readme for asterisk-22.8.1
+Readme for asterisk-22.8.2
The Asterisk(R) Open Source PBX
By Mark Spencer <markster@digium.com> and the Asterisk.org developer community.
Copyright (C) 2001-2025 Sangoma Technologies Corporation and other copyright holders.
@@ -37,7 +37,7 @@ hardware.