{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/kamailio-5.8.8-6.0.7-6.1.4-6.2.0-dev1-and-earlier/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kamailio:kamailio:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.3,"id":"CVE-2026-93962"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Kamailio (5.8.8, 6.0.7, 6.1.4, 6.2.0-dev1 and earlier)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","network"],"_cs_type":"threat","_cs_vendors":["Kamailio"],"content_html":"\u003cp\u003eKamailio is vulnerable to a heap-based buffer overflow within the CDP Diameter Receiver component, specifically impacting the shm_malloc function located in 'src/modules/cdp/receiver.c'. This vulnerability, identified as CVE-2026-93962, affects Kamailio versions up to 5.8.8, 6.0.7, 6.1.4, and 6.2.0-dev1. An unauthenticated remote attacker can exploit this flaw by sending specially crafted Diameter protocol messages to the receiver, leading to heap memory corruption. Publicly available exploit code has been reported, increasing the risk of active exploitation. Defenders should prioritize patching, as the vulnerability resides in core signaling handling components often exposed to network traffic. Successful exploitation could result in service instability or remote code execution, depending on the memory layout and attacker control over the overflowed data.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a high risk to telecommunications and VoIP infrastructure relying on Kamailio for Diameter signaling. A successful exploit can lead to unauthorized code execution, allowing for lateral movement within the network, or persistent denial of service by crashing the process. Given the public availability of exploit code, any internet-facing or unsegmented Kamailio instance is at immediate risk of compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Kamailio to version 6.0.8 or the latest stable releases (\u0026gt;= 5.8.9, \u0026gt;= 6.0.8, \u0026gt;= 6.1.5, \u0026gt;= 6.2.0-dev2) which contain the official patches for CVE-2026-93962.\u003c/li\u003e\n\u003cli\u003eApply the vendor-provided patch (38711a3e788de0130d48cb485578c482b57d9351) if a full version upgrade is not immediately feasible.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation and access control lists (ACLs) to limit access to the Diameter signaling port (typically 3868) to only known, authorized peers.\u003c/li\u003e\n\u003cli\u003eMonitor Kamailio process logs for frequent unexpected restarts or segment faults (SIGSEGV), which may indicate exploitation attempts or service crashes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-20T06:18:06Z","date_published":"2026-09-20T06:18:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-kamailio-buffer-overflow/","summary":"A heap-based buffer overflow vulnerability in the Kamailio CDP Diameter Receiver module (CVE-2026-93962) allows unauthenticated remote attackers to achieve potential code execution or denial of service.","title":"Remote Heap-Based Buffer Overflow in Kamailio CDP Diameter Receiver","url":"https://feed.craftedsignal.io/briefs/2026-09-kamailio-buffer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Kamailio (5.8.8, 6.0.7, 6.1.4, 6.2.0-Dev1 and Earlier)","version":"https://jsonfeed.org/version/1.1"}