CVE-2025-12207 | Kamailio 5.5 Grammar Rule src/core/cfg.y yyerror_at null pointer dereference (EUVD-2025-36068 / Nessus ID 271828)
A vulnerability categorized as problematic has been discovered in Kamailio 5.5. This affects the function yyerror_at of the file src/core/cfg.y of the component Grammar Rule Handler. Such manipulation leads to null pointer dereference.
This vulnerability is documented as CVE-2025-12207. The attack needs to be performed locally. Additionally, an exploit exists.
The actual existence of this vulnerability is currently in question.
This attack requires manipulating config files which might not be a realistic scenario in many cases. The vendor was contacted early about this disclosure but did not respond in any way.