CVE-2025-12205 | Kamailio 5.5 Configuration File src/core/cfg.lex sr_push_yy_state use after free (EUVD-2025-36071 / Nessus ID 271819)
A vulnerability was found in Kamailio 5.5. It has been declared as problematic. The affected element is the function sr_push_yy_state of the file src/core/cfg.lex of the component Configuration File Handler. The manipulation results in use after free.
This vulnerability is cataloged as CVE-2025-12205. The attack must be initiated from a local position. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.
This attack requires manipulating config files which might not be a realistic scenario in many cases. The vendor was contacted early about this disclosure but did not respond in any way.