Kamailio · Kamailio · CVE-2026-82608
**Name of the Vulnerable Software and Affected Versions**
Kamailio versions prior to 5.5.1
Kamailio versions prior to 6.0.8
**Description**
A remote out-of-bounds read can occur within the AVP Handler component. The issue resides in the `get 4bytes()` function located in the `src/modules/ims registrar scscf/cxdx avp.c` file. An out-of-bounds read occurs when a program reads data past the end of the intended buffer, potentially exposing sensitive information from the system memory.
**Recommendations**
Apply patch abb5d60af6eefbd367bf6588c5589566b090e272 for versions prior to 5.5.1.
Apply patch abb5d60af6eefbd367bf6588c5589566b090e272 for versions prior to 6.0.8.