Out-of-Bounds Read Vulnerability in Kamailio SIP Signaling Server
CVE-2026-39864
4.4MEDIUM
What is CVE-2026-39864?
An out-of-bounds read vulnerability exists in the auth module of Kamailio SIP Signaling Server, leading to potential denial of service. This occurs when attackers send specially crafted SIP packets, causing the server to crash if the user authentication process is followed by additional identity checks without a database backend. The issue affects Kamailio versions prior to 6.0.5 and 5.8.7 and has been effectively resolved in these updates.
Affected Version(s)
kamailio < 5.8.7 < 5.8.7
kamailio >= 6.0.0, < 6.0.5 < 6.0.0, 6.0.5
