CVE-2026-93962 Details
Description
A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 6.0.8 is sufficient to resolve this issue. This patch is called 38711a3e788de0130d48cb485578c482b57d9351/4f62235b6f477b649c5cc18b0c81b4e26c949b98/4f62235b6f477b649c5cc18b0c81b4e26c949b98. You should upgrade the affected component.
A heap-based buffer overflow vulnerability has been identified in Kamailio versions through 5.8.8, 6.0.7, 6.1.4, and 6.2.0-dev1. The issue arises in the CDP Diameter Receiver module, specifically within the 'shm_malloc' function in 'src/modules/cdp/receiver.c'. The vulnerability can be exploited remotely by sending a crafted Diameter message with a length field indicating less than 20 bytes, which triggers the overflow by misaligning the allocated buffer size with the actual header size. This flaw occurs before any application-level authentication, making it particularly critical.
Users are advised to upgrade to Kamailio version 6.0.8, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 20, 2026CISA-ADP
Assessed Sep 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/kamailio/kamailio/ | [email protected] | Vendor |
| https://github.com/kamailio/kamailio/commit/38711a3e788de0130d48cb485578c482b57d9351 | [email protected] | Source CodeVendor |
| https://github.com/kamailio/kamailio/issues/4876 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/kamailio/kamailio/pull/4877 | [email protected] | Issue TrackingVendor |
| https://github.com/kamailio/kamailio/releases/tag/6.0.8 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-93962 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/944244 | [email protected] | Permission Required |
| https://vuldb.com/vuln/407921 | [email protected] | Permission Required |
| https://vuldb.com/vuln/407921/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Kamailio | <= 5.8.8 (semver) <= 6.0.7 (semver) <= 6.1.4 (semver) <= 6.2.0-dev1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | CVE Modified | CISA-ADP |
| Sep 20, 2026 | New CVE Received | [email protected] |
Volerion