A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get4bytes of the file src/modules/imsregistrarscscf/cxdxavp.c of the component AVP Handler. Executing a manipulation can lead to out-of-bounds read. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This patch is called abb5d60af6eefbd367bf6588c5589566b090e272. It is advisable to implement a patch to correct this issue. The vendor points out, that "[v]ersion 5.5.0 is old and not maintained anymore."
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82608.json",
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-119",
"CWE-125"
]
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "5.0"
},
{
"last_affected": "5.0"
},
{
"introduced": "5.1"
},
{
"last_affected": "5.1"
},
{
"introduced": "5.2"
},
{
"last_affected": "5.2"
},
{
"introduced": "5.3"
},
{
"last_affected": "5.3"
},
{
"introduced": "5.4"
},
{
"last_affected": "5.4"
},
{
"introduced": "5.5.0"
},
{
"last_affected": "5.5.0"
},
{
"introduced": "6.0.0"
},
{
"last_affected": "6.0.0"
},
{
"introduced": "6.0.1"
},
{
"last_affected": "6.0.1"
},
{
"introduced": "6.0.2"
},
{
"last_affected": "6.0.2"
},
{
"introduced": "6.0.3"
},
{
"last_affected": "6.0.3"
},
{
"introduced": "6.0.4"
},
{
"last_affected": "6.0.4"
},
{
"introduced": "6.0.5"
},
{
"last_affected": "6.0.5"
},
{
"introduced": "6.0.6"
},
{
"last_affected": "6.0.6"
},
{
"introduced": "6.0.7"
},
{
"last_affected": "6.0.7"
}
]
}
[
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1830.0,
"function_hash": "174302063829791650609400154178335499643"
},
"id": "CVE-2026-82608-79971005",
"target": {
"function": "cxdx_get_capabilities",
"file": "src/modules/ims_registrar_scscf/cxdx_avp.c"
},
"source": "https://github.com/kamailio/kamailio/commit/abb5d60af6eefbd367bf6588c5589566b090e272",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 496.0,
"function_hash": "88466524139867693601301764999096137517"
},
"id": "CVE-2026-82608-868be022",
"target": {
"function": "cxdx_get_experimental_result_code",
"file": "src/modules/ims_registrar_scscf/cxdx_avp.c"
},
"source": "https://github.com/kamailio/kamailio/commit/abb5d60af6eefbd367bf6588c5589566b090e272",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 235.0,
"function_hash": "180799538817205538986686197257982677030"
},
"id": "CVE-2026-82608-8764139d",
"target": {
"function": "cxdx_get_sip_number_auth_items",
"file": "src/modules/ims_registrar_scscf/cxdx_avp.c"
},
"source": "https://github.com/kamailio/kamailio/commit/abb5d60af6eefbd367bf6588c5589566b090e272",
"signature_version": "v1"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"307754892165454922567988602329345093387",
"191623869508671415269781471016446354471",
"278516704239885729863001985259036422653",
"19249177308081038713473475042993168725",
"174896205381570263217224849655453786060",
"110731884822685367862778001376473880972",
"337767586938615576086696978891029167878",
"293970921810623732400352218594942792014",
"304294950182384949407592993665287402797",
"123210535806162459079285545760390683031",
"160735721300483912398162103294824421259",
"60941673402757430093821616371387530131",
"98872658961975587949178877686661207401",
"271413008548302877651777668701824244837",
"326323714918859515581373150732685998023",
"131411326428682090275918233962140337708",
"62554529636946447262002026155500616618",
"181972096686193507669595325660563966143",
"253775141274391062573890549951248367050",
"316285114545955843887182933277941817133",
"19249177308081038713473475042993168725"
],
"threshold": 0.9
},
"id": "CVE-2026-82608-8d4398f3",
"target": {
"file": "src/modules/ims_registrar_scscf/cxdx_avp.c"
},
"source": "https://github.com/kamailio/kamailio/commit/abb5d60af6eefbd367bf6588c5589566b090e272",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 204.0,
"function_hash": "71348089025051908893304855945187940399"
},
"id": "CVE-2026-82608-af02ab5c",
"target": {
"function": "cxdx_get_result_code",
"file": "src/modules/ims_registrar_scscf/cxdx_avp.c"
},
"source": "https://github.com/kamailio/kamailio/commit/abb5d60af6eefbd367bf6588c5589566b090e272",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82608.json"
"2026-09-01T08:20:15Z"