7.4

CVE-2026-82608

Exploit

Kamailio AVP cxdx_avp.c get_4bytes out-of-bounds

A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get_4bytes of the file src/modules/ims_registrar_scscf/cxdx_avp.c of the component AVP Handler. Executing a manipulation can lead to out-of-bounds read. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This patch is called abb5d60af6eefbd367bf6588c5589566b090e272. It is advisable to implement a patch to correct this issue. The vendor points out, that "[v]ersion 5.5.0 is old and not maintained anymore."
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellern/a
≫
Produkt Kamailio
Version 5.0
Status affected
Version 5.1
Status affected
Version 5.2
Status affected
Version 5.3
Status affected
Version 5.4
Status affected
Version 5.5.0
Status affected
Version 6.0.0
Status affected
Version 6.0.1
Status affected
Version 6.0.2
Status affected
Version 6.0.3
Status affected
Version 6.0.4
Status affected
Version 6.0.5
Status affected
Version 6.0.6
Status affected
Version 6.0.7
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.141
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cna@vuldb.com 2.1 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cna@vuldb.com 7.4 3.1 3.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
cna@vuldb.com 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://vuldb.com/vuln/397109
https://vuldb.com/vuln/397109/cti
https://vuldb.com/cve/CVE-2026-82608
https://vuldb.com/submit/892903
https://github.com/kamailio/kamailio/issues/4816
https://github.com/Kamailio/Kamailio/pull/4823
https://github.com/Kamailio/Kamailio/commit/abb5d60af6eefbd367bf6588c5589566b090e272
https://github.com/kamailio/kamailio/