I don't know the Kamailio internals but after that commit this crash does not occur...
#0 0x00007f5189cb5475 in raise () from /lib/x86_64-linux-gnu/libc.so.6
(gdb) bt
#0 0x00007f5189cb5475 in raise () from /lib/x86_64-linux-gnu/libc.so.6
#1 0x00007f5189cb86f0 in abort () from /lib/x86_64-linux-gnu/libc.so.6
#2 0x000000000057063f in qm_debug_frag (qm=qm@entry=0x7f5189882010, f=f@entry=0x7f518995ba78) at mem/q_malloc.c:142
#3 0x00000000005716bd in qm_malloc (qm=0x7f5189882010, size=<optimized out>, size@entry=1024,
file=file@entry=0x5f997e "<core>: action.c", func=func@entry=0x5fac10 "do_action", line=line@entry=832) at mem/q_malloc.c:386
#4 0x0000000000423c61 in do_action (h=h@entry=0x7fff62578740, a=a@entry=0x7fff62578820, msg=0x7f5189958e08) at action.c:832
#5 0x00007f5186bc7347 in pv_set_ruri_user (msg=<optimized out>, param=<optimized out>, op=<optimized out>, val=0x7fff62578990)
at pv_core.c:2073
#6 0x000000000047a3ad in lval_pvar_assign (rv=0x7f51899491f0, msg=0x7f5189958e08, h=<optimized out>, lv=<optimized out>) at lvalue.c:362
#7 lval_assign (h=h@entry=0x7fff6257b490, msg=msg@entry=0x7f5189958e08, lv=0x7f5189948ae0, rve=0x7f51899491e8) at lvalue.c:410
#8 0x00000000004212f0 in do_action (h=h@entry=0x7fff6257b490, a=a@entry=0x7f5189948c48, msg=msg@entry=0x7f5189958e08) at action.c:1478
#9 0x0000000000420940 in run_actions (h=h@entry=0x7fff6257b490, a=0x7f518993dfc0, msg=msg@entry=0x7f5189958e08) at action.c:1599
#10 0x0000000000421d7b in do_action (h=h@entry=0x7fff6257b490, a=a@entry=0x7f518994aaf0, msg=msg@entry=0x7f5189958e08) at action.c:1094
#11 0x0000000000420940 in run_actions (h=h@entry=0x7fff6257b490, a=0x7f518994aaf0, msg=msg@entry=0x7f5189958e08) at action.c:1599
#12 0x0000000000421d7b in do_action (h=h@entry=0x7fff6257b490, a=a@entry=0x7f518994af30, msg=msg@entry=0x7f5189958e08) at action.c:1094
#13 0x0000000000420940 in run_actions (h=h@entry=0x7fff6257b490, a=0x7f518993ba90, msg=msg@entry=0x7f5189958e08) at action.c:1599
#14 0x0000000000421ef8 in do_action (h=h@entry=0x7fff6257b490, a=a@entry=0x7f51898fe0a0, msg=msg@entry=0x7f5189958e08) at action.c:715
#15 0x0000000000420940 in run_actions (h=h@entry=0x7fff6257b490, a=0x7f51898fc8e0, msg=msg@entry=0x7f5189958e08) at action.c:1599
#16 0x0000000000422428 in do_action (h=h@entry=0x7fff6257b490, a=a@entry=0x7f5189901bd0, msg=msg@entry=0x7f5189958e08) at action.c:1365
#17 0x0000000000420940 in run_actions (h=h@entry=0x7fff6257b490, a=0x7f51898fbfb8, msg=msg@entry=0x7f5189958e08) at action.c:1599
#18 0x0000000000421d7b in do_action (h=h@entry=0x7fff6257b490, a=a@entry=0x7f5189901df0, msg=msg@entry=0x7f5189958e08) at action.c:1094
#19 0x0000000000420940 in run_actions (h=h@entry=0x7fff6257b490, a=0x7f51898f92b8, msg=msg@entry=0x7f5189958e08) at action.c:1599
#20 0x0000000000421ef8 in do_action (h=h@entry=0x7fff6257b490, a=a@entry=0x7f51898e1e68, msg=msg@entry=0x7f5189958e08) at action.c:715
#21 0x0000000000420940 in run_actions (h=h@entry=0x7fff6257b490, a=0x7f51898e0c48, msg=msg@entry=0x7f5189958e08) at action.c:1599
#22 0x0000000000421d7b in do_action (h=h@entry=0x7fff6257b490, a=a@entry=0x7f51898e3918, msg=msg@entry=0x7f5189958e08) at action.c:1094
#23 0x0000000000420940 in run_actions (h=h@entry=0x7fff6257b490, a=a@entry=0x7f51898d9680, msg=msg@entry=0x7f5189958e08) at action.c:1599
#24 0x0000000000429a50 in run_top_route (a=0x7f51898d9680, msg=msg@entry=0x7f5189958e08, c=c@entry=0x0) at action.c:1685
#25 0x00000000004bbb9e in receive_msg (buf=<optimized out>, len=<optimized out>, rcv_info=<optimized out>) at receive.c:212
#26 0x000000000055fe21 in udp_rcv_loop () at udp_server.c:536