[Git][security-tracker-team/security-tracker][master] Add two kamailio issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 4 21:23:38 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
11a810d9 by Salvatore Bonaccorso at 2026-09-04T22:23:12+02:00
Add two kamailio issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3445,9 +3445,19 @@ CVE-2026-52130 (llama.cpp b5693 and before is vulnerable to Uncontrolled Recursi
 CVE-2026-52111 (An issue in fast-note-sync-service <=2.13.7 allows a remote attacker t ...)
 	NOT-FOR-US: fast-note-sync-service
 CVE-2026-52023 (An issue in kamailio v.6.1.1 and before allows a remote attacker to ca ...)
-	TODO: check
+	- kamailio 6.1.4-1
+	NOTE: https://github.com/kamailio/kamailio/issues/4671
+	NOTE: Fixed by: https://github.com/kamailio/kamailio/commit/66e0b5075dc741095bf3439e76d25833f8f82e52 (6.1.3)
+	NOTE: Fixed by: https://github.com/kamailio/kamailio/commit/72e19957e2097b5a96ef50437dde9fae75077a63 (6.1.3)
+	NOTE: Fixed by: https://github.com/kamailio/kamailio/commit/bb74017208cdefdbc397d8b2474b73bde70e29f9 (6.1.3)
+	NOTE: Fixed by: https://github.com/kamailio/kamailio/commit/0acd0f025c4e190b6252ad898fce8dd7bc4ac311 (6.1.4)
 CVE-2026-52022 (An issue in kamailio v.6.1.1 and before allows a remote attacker to ca ...)
-	TODO: check
+	- kamailio 6.1.4-1
+	NOTE: https://github.com/kamailio/kamailio/issues/4670
+	NOTE: Fixed by: https://github.com/kamailio/kamailio/commit/d04659303e7fbfb55d0884dedc6dde6ceac7c51b (6.1.3)
+	NOTE: Fixed by: https://github.com/kamailio/kamailio/commit/e47d4792de562b767d0796662525da902b270df3 (6.1.3)
+	NOTE: Fixed by: https://github.com/kamailio/kamailio/commit/de4fc33ce90c3c11382eff3e8dc4789e0ec8c084 (6.1.3)
+	NOTE: Fixed by: https://github.com/kamailio/kamailio/commit/8fa4d72fa9a93662bbe0d4acd65c2158509c4935 (6.1.4)
 CVE-2026-51974 (An eval() injection vulnerability in the get_list function in modules/ ...)
 	NOT-FOR-US: Fooocus
 CVE-2026-51956 (A Broken Object Level Authorization vulnerability exists in Grashjs At ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/11a810d91667f3027399a1d7dd968c16a257e3d8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/11a810d91667f3027399a1d7dd968c16a257e3d8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/d0799330/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list