#1149730 kamailio: CVE-2026-93962

Package:
src:kamailio
Source:
src:kamailio
Submitter:
Salvatore Bonaccorso
Date:
2026-10-08 17:39:19 UTC
Severity:
normal
Tags:
#1149730#5
Date:
2026-10-02 18:53:15 UTC
From:
To:
Hi,

The following vulnerability was published for kamailio.

CVE-2026-93962[0]:
| A weakness has been identified in Kamailio up to
| 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function
| shm_malloc of the file src/modules/cdp/receiver.c of the component
| CDP Diameter Receiver. Executing a manipulation can lead to heap-
| based buffer overflow. It is possible to launch the attack remotely.
| The exploit has been made available to the public and could be used
| for attacks. Upgrading to version 6.0.8 is sufficient to resolve
| this issue. This patch is called 38711a3e788de0130d48cb485578c482b57
| d9351/4f62235b6f477b649c5cc18b0c81b4e26c949b98/4f62235b6f477b649c5cc
| 18b0c81b4e26c949b98. You should upgrade the affected component.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-93962
https://www.cve.org/CVERecord?id=CVE-2026-93962
[1] https://github.com/kamailio/kamailio/issues/4876
[2] https://github.com/kamailio/kamailio/pull/4877
[3] https://github.com/kamailio/kamailio/commit/38711a3e788de0130d48cb485578c482b57d9351

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore