PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93962 Kamailio Project CVE debrief

A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 6.0.8 is sufficient to resolve this issue.

Vendor
Kamailio Project
Product
Kamailio
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-20
Original CVE updated
2026-09-20
Advisory published
2026-09-20
Advisory updated
2026-09-20

Who should care

Administrators and users of Kamailio versions up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1 should assess exposure and upgrade to version 6.0.8. Security teams and vulnerability management teams should review the vulnerability details and plan for remediation. IT operators and system administrators responsible for Kamailio deployments should verify patch application and monitor for suspicious activity. Network defenders should review relevant monitoring, detection,

Why it matters

CVE-2026-93962 is a weakness in Kamailio's CDP Diameter Receiver that can lead to heap-based buffer overflow. Defenders should assess exposure, prioritize upgrading to version 6.0.8, and monitor for suspicious activity.

  • Remote attackers could exploit this vulnerability to execute heap-based buffer overflow attacks
  • Successful exploitation could lead to denial of service or code execution
  • Defenders should prioritize upgrading to version 6.0.8 to prevent exploitation
  • Verify patch application and monitor for suspicious activity

Technical summary

The function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver in Kamailio is vulnerable to heap-based buffer overflow due to improper handling of memory allocation. This vulnerability can be exploited remotely, potentially leading to denial of service or code execution. Upgrading to version 6.0.8 is sufficient to resolve this issue. The patch 38711a3e788de0130d48cb485578c482b57d9351 has been made available to address this vulnerability. Defenders should assess exposure and prioritize upgrading to version 6.0.8.

Defensive priority

Upgrade to version 6.0.8 to resolve this issue.

Recommended defensive actions

  • Upgrade to version 6.0.8
  • Review and apply the patch 38711a3e788de0130d48cb485578c482b57d9351
  • Monitor for remote attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD vulnerability detail page provide information about the weakness in Kamailio. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Evidence is limited to public CVE and NVD source detail. Defenders should verify patch application, assess exposure, and monitor for suspicious activity related to heap-based buffer overflow attacks.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93962 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93962

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93962 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93962

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.