8.3
CVE-2026-93962
- EPSS 0.53%
- Veröffentlicht 20.09.2026 05:16:29
- Zuletzt bearbeitet 22.09.2026 17:17:30
- Erkennungen
Kamailio CDP Diameter Receiver receiver.c shm_malloc heap-based overflow
A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 6.0.8 is sufficient to resolve this issue. This patch is called 38711a3e788de0130d48cb485578c482b57d9351/4f62235b6f477b649c5cc18b0c81b4e26c949b98/4f62235b6f477b649c5cc18b0c81b4e26c949b98. You should upgrade the affected component.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellern/a
≫
Produkt
Kamailio
Version
5.8.0
Status
affected
Version
5.8.1
Status
affected
Version
5.8.2
Status
affected
Version
5.8.3
Status
affected
Version
5.8.4
Status
affected
Version
5.8.5
Status
affected
Version
5.8.6
Status
affected
Version
5.8.7
Status
affected
Version
5.8.8
Status
affected
Version
6.0.0
Status
affected
Version
6.0.1
Status
affected
Version
6.0.2
Status
affected
Version
6.0.3
Status
affected
Version
6.0.4
Status
affected
Version
6.0.5
Status
affected
Version
6.0.6
Status
affected
Version
6.0.7
Status
affected
Version
6.1.0
Status
affected
Version
6.1.1
Status
affected
Version
6.1.2
Status
affected
Version
6.1.3
Status
affected
Version
6.1.4
Status
affected
Version
6.2.0-dev1
Status
affected
Version
6.0.8
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.53% | 0.437 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@vuldb.com | 5.5 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| cna@vuldb.com | 8.3 | 3.9 | 3.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
|
| cna@vuldb.com | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CWE-122 Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
https://github.com/kamailio/kamailio/
https://github.com/kamailio/kamailio/commit/38711a3e788de0130d48cb485578c482b57d9351
https://github.com/kamailio/kamailio/issues/4876
https://github.com/kamailio/kamailio/pull/4877
https://github.com/kamailio/kamailio/releases/tag/6.0.8
https://vuldb.com/cve/CVE-2026-93962
https://vuldb.com/submit/944244
https://vuldb.com/vuln/407921
https://vuldb.com/vuln/407921/cti