PT-2026-95909 · Kamailio · Kamailio
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Kamailio versions prior to 6.0.8
Description
A heap-based buffer overflow can be triggered remotely within the CDP Diameter Receiver component. The issue resides in the
shm malloc() function located in the src/modules/cdp/receiver.c file. A heap-based buffer overflow occurs when a program writes more data to a heap-allocated memory block than it can hold, potentially leading to crashes or arbitrary code execution.Recommendations
Upgrade to version 6.0.8.
As a temporary mitigation, restrict access to the CDP Diameter Receiver component.
Exploit
Fix
Buffer Overflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kamailio