CVE-2025-12205 | Kamailio 5.5 Configuration File src/core/cfg.lex sr_push_yy_state use after free
A vulnerability was found in Kamailio 5.5. It has been declared as problematic. The affected element is the function sr_push_yy_state of the file src/core/cfg.lex of the component Configuration File Handler. The manipulation results in use after free.
This vulnerability is cataloged as CVE-2025-12205. The attack must be initiated from a local position. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.