A vulnerability has been found in Kamailio 5.5. This affects the function yyerror_at of the file src/core/cfg.y of the component Grammar Rule Handler. Such manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed to the public and may be used. The actual existence of this vulnerability is currently in question. This attack requires manipulating config files which might not be a realistic scenario in many cases. The vendor was contacted early about this disclosure but did not respond in any way.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Nov 2025 07:30:00 +0900


Tue, 04 Nov 2025 08:15:00 +0900

Type Values Removed Values Added
Description A vulnerability has been found in Kamailio 5.5. This affects the function yyerror_at of the file src/core/cfg.y of the component Grammar Rule Handler. Such manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. A vulnerability has been found in Kamailio 5.5. This affects the function yyerror_at of the file src/core/cfg.y of the component Grammar Rule Handler. Such manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed to the public and may be used. The actual existence of this vulnerability is currently in question. This attack requires manipulating config files which might not be a realistic scenario in many cases. The vendor was contacted early about this disclosure but did not respond in any way.
References

Wed, 29 Oct 2025 18:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Oct 2025 00:00:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:kamailio:kamailio:5.5.0:*:*:*:*:*:*:*

Tue, 28 Oct 2025 23:30:00 +0900

Type Values Removed Values Added
References

Tue, 28 Oct 2025 10:30:00 +0900

Type Values Removed Values Added
References

Tue, 28 Oct 2025 07:30:00 +0900

Type Values Removed Values Added
First Time appeared Kamailio
Kamailio kamailio
Vendors & Products Kamailio
Kamailio kamailio

Mon, 27 Oct 2025 12:15:00 +0900

Type Values Removed Values Added
Description A vulnerability has been found in Kamailio 5.5. This affects the function yyerror_at of the file src/core/cfg.y of the component Grammar Rule Handler. Such manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Kamailio Grammar Rule cfg.y yyerror_at null pointer dereference
Weaknesses CWE-404
CWE-476
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-11-04T21:09:31.867Z

Reserved: 2025-10-25T11:52:20.560Z

Link: CVE-2025-12207

cve-icon Vulnrichment

Updated: 2025-11-04T21:09:31.867Z

cve-icon NVD

Status : Modified

Published: 2025-10-27T03:15:49.937

Modified: 2025-11-04T22:16:06.180

Link: CVE-2025-12207

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-28T07:06:44Z

Weaknesses