Debian Package Tracker
Register | Log in
Subscribe

kamailio

very fast, dynamic and configurable SIP server

Choose email to subscribe with

general
  • source: kamailio (main)
  • version: 6.1.4-1
  • maintainer: Debian VoIP Team (archive) (DMD)
  • uploaders: Victor Seva [DMD]
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 5.4.4-1
  • oldstable: 5.6.3-2
  • stable: 6.0.1-1+deb13u1
  • stable-sec: 6.0.1-1+deb13u2
  • testing: 6.1.4-1
  • unstable: 6.1.4-1
versioned links
  • 5.4.4-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.6.3-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.0.1-1+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.0.1-1+deb13u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.1.4-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • kamailio (2 bugs: 0, 2, 0, 0)
  • kamailio-authblockchain-modules
  • kamailio-autheph-modules
  • kamailio-cnxcc-modules
  • kamailio-cpl-modules
  • kamailio-erlang-modules
  • kamailio-extra-modules
  • kamailio-geoip2-modules
  • kamailio-ims-modules
  • kamailio-json-modules
  • kamailio-kafka-modules
  • kamailio-kazoo-modules
  • kamailio-ldap-modules
  • kamailio-lua-modules
  • kamailio-lwsc-modules
  • kamailio-memcached-modules
  • kamailio-microhttpd-modules
  • kamailio-mongodb-modules
  • kamailio-mqtt-modules
  • kamailio-mysql-modules
  • kamailio-nats-modules
  • kamailio-outbound-modules
  • kamailio-perl-modules
  • kamailio-phonenum-modules
  • kamailio-postgres-modules
  • kamailio-presence-modules
  • kamailio-python3-modules
  • kamailio-rabbitmq-modules
  • kamailio-radius-modules
  • kamailio-redis-modules
  • kamailio-ruby-modules
  • kamailio-sctp-modules
  • kamailio-secsipid-modules
  • kamailio-snmpstats-modules
  • kamailio-sqlite-modules
  • kamailio-systemd-modules
  • kamailio-tls-modules
  • kamailio-unixodbc-modules
  • kamailio-utils-modules
  • kamailio-websocket-modules
  • kamailio-xml-modules
  • kamailio-xmpp-modules
action needed
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-93962: A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 6.0.8 is sufficient to resolve this issue. This patch is called 38711a3e788de0130d48cb485578c482b57d9351/4f62235b6f477b649c5cc18b0c81b4e26c949b98/4f62235b6f477b649c5cc18b0c81b4e26c949b98. You should upgrade the affected component.
Created: 2026-09-20 Last update: 2026-09-22 21:00
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-93962: A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 6.0.8 is sufficient to resolve this issue. This patch is called 38711a3e788de0130d48cb485578c482b57d9351/4f62235b6f477b649c5cc18b0c81b4e26c949b98/4f62235b6f477b649c5cc18b0c81b4e26c949b98. You should upgrade the affected component.
Created: 2026-09-20 Last update: 2026-09-22 21:00
6 security issues in bookworm high

There are 6 open security issues in bookworm.

6 important issues:
  • CVE-2026-39863: Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted data packet sent over TCP. The issue impacts Kamailio instances having TCP or TLS listeners. This vulnerability is fixed in 5.1.1, 6.0.6, and 5.8.8.
  • CVE-2026-39864: Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.0.5 and 5.8.7, an out-of-bounds read in the auth module of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted SIP packet if a successful user authentication without a database backend is followed by additional user identity checks. This vulnerability is fixed in 6.0.5 and 5.8.7.
  • CVE-2026-52022: An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling components
  • CVE-2026-52023: An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree()
  • CVE-2026-82608: A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get_4bytes of the file src/modules/ims_registrar_scscf/cxdx_avp.c of the component AVP Handler. Executing a manipulation can lead to out-of-bounds read. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This patch is called abb5d60af6eefbd367bf6588c5589566b090e272. It is advisable to implement a patch to correct this issue. The vendor points out, that "[v]ersion 5.5.0 is old and not maintained anymore."
  • CVE-2026-93962: A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 6.0.8 is sufficient to resolve this issue. This patch is called 38711a3e788de0130d48cb485578c482b57d9351/4f62235b6f477b649c5cc18b0c81b4e26c949b98/4f62235b6f477b649c5cc18b0c81b4e26c949b98. You should upgrade the affected component.
Created: 2026-04-09 Last update: 2026-09-22 21:00
3 security issues in bullseye high

There are 3 open security issues in bullseye.

3 important issues:
  • CVE-2026-39863: Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted data packet sent over TCP. The issue impacts Kamailio instances having TCP or TLS listeners. This vulnerability is fixed in 5.1.1, 6.0.6, and 5.8.8.
  • CVE-2026-39864: Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.0.5 and 5.8.7, an out-of-bounds read in the auth module of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted SIP packet if a successful user authentication without a database backend is followed by additional user identity checks. This vulnerability is fixed in 6.0.5 and 5.8.7.
  • CVE-2026-82608: A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get_4bytes of the file src/modules/ims_registrar_scscf/cxdx_avp.c of the component AVP Handler. Executing a manipulation can lead to out-of-bounds read. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This patch is called abb5d60af6eefbd367bf6588c5589566b090e272. It is advisable to implement a patch to correct this issue. The vendor points out, that "[v]ersion 5.5.0 is old and not maintained anymore."
Created: 2026-04-09 Last update: 2026-08-31 12:02
Depends on packages which need a new maintainer normal
The packages that kamailio depends on which need a new maintainer are:
  • docbook-xsl (#802370)
    • Build-Depends: docbook-xsl
Created: 2021-10-12 Last update: 2026-09-27 13:00
lintian reports 2 warnings normal
Lintian reports 2 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-08-20 Last update: 2026-08-20 21:18
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-93962: (postponed; to be fixed through a stable update) A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 6.0.8 is sufficient to resolve this issue. This patch is called 38711a3e788de0130d48cb485578c482b57d9351/4f62235b6f477b649c5cc18b0c81b4e26c949b98/4f62235b6f477b649c5cc18b0c81b4e26c949b98. You should upgrade the affected component.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-09-20 Last update: 2026-09-22 21:00
debian/patches: 2 patches to forward upstream low

Among the 2 debian patches available in version 6.1.4-1 of the package, we noticed the following issues:

  • 2 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-08-20 23:30
testing migrations
  • This package will soon be part of the auto-perl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • This package will soon be part of the auto-libsecp256k1 transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • This package will soon be part of the auto-nats.c transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2026-09-11] Accepted kamailio 6.0.1-1+deb13u2 (source amd64) into stable-security (Debian FTP Masters) (signed by: Victor Seva)
  • [2026-08-28] kamailio 6.1.4-1 MIGRATED to testing (Debian testing watch)
  • [2026-08-20] Accepted kamailio 6.1.4-1 (source) into unstable (Victor Seva)
  • [2026-06-11] kamailio 6.1.3-2 MIGRATED to testing (Debian testing watch)
  • [2026-06-06] Accepted kamailio 6.1.3-2 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2026-06-02] kamailio 6.1.3-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-27] Accepted kamailio 6.1.3-1 (source) into unstable (Victor Seva)
  • [2026-04-28] kamailio 6.1.2-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-22] Accepted kamailio 6.1.2-1 (source) into unstable (Victor Seva)
  • [2026-04-18] kamailio 6.1.1-2.1 MIGRATED to testing (Debian testing watch)
  • [2026-04-13] Accepted kamailio 6.1.1-2.1 (source) into unstable (Adrian Bunk)
  • [2026-04-02] Accepted kamailio 6.1.1-2 (source amd64) into unstable (Debian FTP Masters) (signed by: Victor Seva)
  • [2026-01-25] kamailio 6.0.5-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-13] Accepted kamailio 6.0.5-1 (source) into unstable (Victor Seva)
  • [2025-11-12] kamailio 6.0.4-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-06] Accepted kamailio 6.0.4-1 (source) into unstable (Victor Seva)
  • [2025-10-19] kamailio 6.0.3-3 MIGRATED to testing (Debian testing watch)
  • [2025-10-14] Accepted kamailio 6.0.3-3 (source) into unstable (Victor Seva)
  • [2025-09-16] kamailio 6.0.3-2 MIGRATED to testing (Debian testing watch)
  • [2025-09-11] Accepted kamailio 6.0.3-2 (source) into unstable (Victor Seva)
  • [2025-09-11] Accepted kamailio 6.0.3-1 (source) into unstable (Victor Seva)
  • [2025-09-03] kamailio 6.0.2-3 MIGRATED to testing (Debian testing watch)
  • [2025-08-31] Accepted kamailio 6.0.1-1+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: bage@debian.org)
  • [2025-08-28] Accepted kamailio 6.0.2-3 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2025-08-13] kamailio 6.0.2-2 MIGRATED to testing (Debian testing watch)
  • [2025-07-24] Accepted kamailio 6.0.2-2 (source) into unstable (Victor Seva)
  • [2025-07-24] Accepted kamailio 6.0.2-1 (source) into unstable (Victor Seva)
  • [2025-03-17] kamailio 6.0.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-11] Accepted kamailio 6.0.1-1 (source) into unstable (Victor Seva)
  • [2025-02-12] Accepted kamailio 6.0.0-1 (source amd64) into unstable (Debian FTP Masters) (signed by: Victor Seva)
  • 1
  • 2
bugs [bug history graph]
  • all: 5
  • RC: 0
  • I&N: 3
  • M&W: 2
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 2)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 6.1.2-1ubuntu4
  • 5 bugs
  • patches for 6.1.2-1ubuntu4

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing