PT-2026-93876 · Git · Open5Gs
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X |
Name of the Vulnerable Software and Affected Versions
Open5GS versions prior to 2.8.1
Description
A remote attack can be initiated against the PFCP Session Report Request Handler component. The issue resides in the
smf n4 handle session report request() function within the src/smf/n4-handler.c file, where specific manipulation leads to a reachable assertion, potentially causing the system to crash.Recommendations
Install the patch identified as e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9.
As a temporary mitigation, restrict access to the
smf n4 handle session report request() function.Exploit
Fix
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open5Gs