PT-2026-83682 · Kamailio · Kamailio

·

CVE-2026-82608

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Kamailio versions prior to 5.5.1 Kamailio versions prior to 6.0.8
Description A remote out-of-bounds read can occur within the AVP Handler component. The issue resides in the get 4bytes() function located in the src/modules/ims registrar scscf/cxdx avp.c file. An out-of-bounds read occurs when a program reads data past the end of the intended buffer, potentially exposing sensitive information from the system memory.
Recommendations Apply patch abb5d60af6eefbd367bf6588c5589566b090e272 for versions prior to 5.5.1. Apply patch abb5d60af6eefbd367bf6588c5589566b090e272 for versions prior to 6.0.8.

Exploit

Fix

Out of bounds Read

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82608

Affected Products

Kamailio