PT-2026-83632 · Open5Gs · Open5Gs
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Open5GS versions prior to 2.8.0
Description
A remote memory corruption issue exists in the AMF component within the
amf namf comm decode ue mm context list() function located in the src/amf/namf-handler.c file. The flaw is triggered by the manipulation of the ueContext.mmContextList[*].allowedNssai argument.Recommendations
Upgrade to version 2.8.0.
As a temporary mitigation, restrict access to the
amf namf comm decode ue mm context list() function to minimize the risk of exploitation.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open5Gs