rootpwn

high · CVSS v3 8.3 · CVSS v4 6.9 · EPSS 0.00529

CVE-2026-93962

Kamailio's CDP Diameter Receiver module contains a heap-based buffer overflow in the shm_malloc function. The flaw can be triggered remotely

Overview

Kamailio's CDP Diameter Receiver module contains a heap-based buffer overflow in the shm_malloc function. The flaw can be triggered remotely and is publicly available. Upgrading to version 6.0.8 or later resolves the issue.

Description

A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 6.0.8 is sufficient to resolve this issue. This patch is called 38711a3e788de0130d48cb485578c482b57d9351/4f62235b6f477b649c5cc18b0c81b4e26c949b98/4f62235b6f477b649c5cc18b0c81b4e26c949b98. You should upgrade the affected component.

Impact

The vulnerability allows attackers to overflow heap memory, potentially leading to arbitrary code execution or denial of service. This compromises confidentiality, integrity, and availability of SIP servers running affected Kamailio versions. Network operators and service providers deploying these versions are at risk.

Remediation

Apply the official patch by upgrading to Kamailio 6.0.8 or later. If an upgrade is not immediately possible, restrict inbound Diameter traffic to trusted peers and monitor for abnormal memory usage. Disable the CDP module if it is not required.

Risk context

Severity is high with CVSS v3 score 8.3 and a low EPSS of 0.00529, indicating a moderate likelihood of exploitation but significant impact if triggered. Defenders should prioritize patching as soon as possible.

Affected products

  • Kamailio 5.8.8
  • Kamailio 6.0.7
  • Kamailio 6.1.4
  • Kamailio 6.2.0-dev1

Scores

Severity
high
CVSS v2
7.5
CVSS v3
8.3
CVSS v4
6.9
EPSS
0.00529

heap-overflow kamailio diameter remote-exploit high-severity public-poc patch network-security

← All CVEs