Hi,
The following vulnerability was published for kamailio.
CVE-2026-93962[0]:
| A weakness has been identified in Kamailio up to
| 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function
| shm_malloc of the file src/modules/cdp/receiver.c of the component
| CDP Diameter Receiver. Executing a manipulation can lead to heap-
| based buffer overflow. It is possible to launch the attack remotely.
| The exploit has been made available to the public and could be used
| for attacks. Upgrading to version 6.0.8 is sufficient to resolve
| this issue. This patch is called 38711a3e788de0130d48cb485578c482b57
| d9351/4f62235b6f477b649c5cc18b0c81b4e26c949b98/4f62235b6f477b649c5cc
| 18b0c81b4e26c949b98. You should upgrade the affected component.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-93962
https://www.cve.org/CVERecord?id=CVE-2026-93962
[1] https://github.com/kamailio/kamailio/issues/4876
[2] https://github.com/kamailio/kamailio/pull/4877
[3] https://github.com/kamailio/kamailio/commit/38711a3e788de0130d48cb485578c482b57d9351
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore