CVE-2026-82608: Kamailio AVP cxdx_avp.c get_4bytes out-of-bounds
A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get4bytes of the file src/modules/imsregistrarscscf/cxdxavp.c of the component AVP Handler. Executing a manipulation can lead to out-of-bounds read. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This patch is called abb5d60af6eefbd367bf6588c5589566b090e272. It is advisable to implement a patch to correct this issue. The vendor points out, that "[v]ersion 5.5.0 is old and not maintained anymore."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kamailio AVP Handlerto a version that resolves this vulnerability.Fixed in 6.0.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch abb5d60af6eefbd367bf6588c5589566b090e272 - Compensating control
Limit network exposure of Kamailio to reduce the risk of remote exploitation (the attack may be performed from remote).
- Operational
Since the exploit is publicly disclosed and may be utilized, monitor Kamailio/IMS Registrar for signs of exploitation after patching.
Event History
Frequently Asked Questions
Which deployments should be prioritized for remediation?
Kamailio deployments using the ims_registrar_scscf AVP Handler component should be prioritized, particularly instances running versions up to 5.5.0 or 6.0.7. Version 5.5.0 is identified by the vendor as old and no longer maintained.
What access does an attacker need?
The issue can be exploited remotely, and the supplied vector indicates low privileges are required. No user interaction is required.
What should be done if an affected version is in use?
Apply the vendor patch identified as abb5d60af6eefbd367bf6588c5589566b090e272. Because public exploit disclosure is reported, patching should be treated as a priority.