<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:kamailio:kamailio:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3akamailiokamailio/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 31 Aug 2026 05:14:29 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3akamailiokamailio/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Out-of-Bounds Read Vulnerability in Kamailio AVP Handler</title><link>https://feed.craftedsignal.io/briefs/2026-08-kamailio-oob-read/</link><pubDate>Mon, 31 Aug 2026 05:14:29 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-kamailio-oob-read/</guid><description>Kamailio versions up to 5.5.0 and 6.0.7 contain an out-of-bounds read vulnerability in the get_4bytes function that allows remote attackers to trigger memory errors.</description><content:encoded><![CDATA[<p>Kamailio versions up to 5.5.0 and 6.0.7 are vulnerable to an out-of-bounds read flaw within the get_4bytes function in the ims_registrar_scscf module (file: src/modules/ims_registrar_scscf/cxdx_avp.c). The AVP Handler component fails to properly validate input during processing, which can be exploited by a remote attacker to induce a crash or potentially leak sensitive memory contents. Publicly available exploit code exists, increasing the risk for environments using unpatched versions of the SIP server. The vendor has highlighted that version 5.5.0 is end-of-life and no longer receives security maintenance, necessitating an upgrade to supported versions for organizations currently relying on these legacy releases.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a significant risk to SIP-based infrastructure relying on affected versions of Kamailio. Successful exploitation may result in service disruption through denial-of-service or the exposure of sensitive memory data, potentially facilitating further exploitation of the host system.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Kamailio to a supported version (6.0.8 or later) immediately, as version 5.5.0 is no longer maintained.</li>
<li>Apply the vendor-provided patch (commit hash: abb5d60af6eefbd367bf6588c5589566b090e272) to custom builds if an immediate upgrade is not feasible.</li>
<li>Monitor logs for repeated crash events or process restarts in the Kamailio service, which may indicate attempts to trigger memory instability via this vulnerability.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category></item></channel></rss>