CVE-2025-12204: Kamailio Configuration File rvalue.c rve_destroy heap-based overflow
A security vulnerability has been detected in Kamailio 5.5. Impacted is the function rvedestroy of the file src/core/rvalue.c of the component Configuration File Handler. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. There is ongoing doubt regarding the real existence of this vulnerability. This attack requires manipulating config files which might not be a realistic scenario in many cases. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12204?
CVE-2025-12204 has a high severity rating due to its potential for local exploitation through heap-based buffer overflow.
How do I fix CVE-2025-12204?
To fix CVE-2025-12204, update Kamailio to the latest version where the vulnerability is patched.
Who is affected by CVE-2025-12204?
CVE-2025-12204 affects all versions of Kamailio 5.5 due to a flaw in the Configuration File Handler.
What type of vulnerability is CVE-2025-12204?
CVE-2025-12204 is classified as a heap-based buffer overflow vulnerability.
Can CVE-2025-12204 be exploited remotely?
No, CVE-2025-12204 requires local access to the system to be exploited.