CVE-2026-82608: Kamailio AVP cxdx_avp.c get_4bytes out-of-bounds

Published Aug 31, 2026
·
Updated

A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get4bytes of the file src/modules/imsregistrarscscf/cxdxavp.c of the component AVP Handler. Executing a manipulation can lead to out-of-bounds read. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This patch is called abb5d60af6eefbd367bf6588c5589566b090e272. It is advisable to implement a patch to correct this issue. The vendor points out, that "[v]ersion 5.5.0 is old and not maintained anymore."

Affected Software

1 affected component
kamailio Kamailio<=5.5.0, <=6.0.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Kamailio AVP Handler to a version that resolves this vulnerability.

    Fixed in 6.0.7
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch abb5d60af6eefbd367bf6588c5589566b090e272
  3. Compensating control

    Limit network exposure of Kamailio to reduce the risk of remote exploitation (the attack may be performed from remote).

  4. Operational

    Since the exploit is publicly disclosed and may be utilized, monitor Kamailio/IMS Registrar for signs of exploitation after patching.

Event History

Aug 31, 2026
CVE Published
via MITRE·02:45 AM
Data Sourced
via MITRE·02:45 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments should be prioritized for remediation?

Kamailio deployments using the ims_registrar_scscf AVP Handler component should be prioritized, particularly instances running versions up to 5.5.0 or 6.0.7. Version 5.5.0 is identified by the vendor as old and no longer maintained.

2

What access does an attacker need?

The issue can be exploited remotely, and the supplied vector indicates low privileges are required. No user interaction is required.

3

What should be done if an affected version is in use?

Apply the vendor patch identified as abb5d60af6eefbd367bf6588c5589566b090e272. Because public exploit disclosure is reported, patching should be treated as a priority.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203