Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-93962— Kamailio CDP Diameter Receiver receiver.c shm_malloc heap-based overflow

Quick assessment

Affected
n/a Kamailio
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Kamailio 5.8.8、6.0.7、6.1.4 及 6.2.0-dev1 版本中发现了安全漏洞。受影响的组件是 CDP Diameter 接收器(CDP Diameter Receiver)中的 函数,位于源文件 中。通过执行特定操作,可能引发堆缓冲区溢出(heap-based buffer overflow)。该漏洞可被远程利用,且已有公开的利用代码(exploit)可供攻击者使用。将版本升级至 6.0.8 即可解决此问题。相关补丁的提交哈希值为: 、 (注:原文中重复列出了两个相同的哈希值 ,可能为笔

CVSS 8.3 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93962

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kamailio CDP Diameter Receiver receiver.c shm_malloc heap-based overflow
Source: CVE Program / CVE List V5
Vulnerability Description
A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 6.0.8 is sufficient to resolve this issue. This patch is called 38711a3e788de0130d48cb485578c482b57d9351/4f62235b6f477b649c5cc18b0c81b4e26c949b98/4f62235b6f477b649c5cc18b0c81b4e26c949b98. You should upgrade the affected component.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
堆缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- Kamailio 5.8.0 cpe:2.3:a:kamailio:kamailio:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-93962

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93962

登录查看更多情报信息。

Patches & Fixes for CVE-2026-93962 (2)

Other References for CVE-2026-93962 (2)

Same Patch Batch · n/a · 2026-09-20 · 3 CVEs total

CVE-2026-94004 7.3 HIGH DedeCMS mytag_js.php code injection
CVE-2026-93960 4.3 MEDIUM Pixelfed OAuth Scope ApiV1Controller.php instancePeers missing authentication

IV. Related Vulnerabilities

V. Comments for CVE-2026-93962

No comments yet


Leave a comment