PT-2026-93893 · Git · Open5Gs

·

CVE-2026-92417

·

Published

2026-09-16

·

Updated

2026-09-22

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X
Name of the Vulnerable Software and Affected Versions Open5GS versions prior to 2.8.1
Description A remote attack can cause a null pointer dereference in the PFCP Handler component. This occurs within the ogs pfcp parse volume measurement() function located in the lib/pfcp/types.c library. A null pointer dereference is a condition where a program attempts to read or write to a memory address that is null, typically leading to a system crash.
Recommendations Apply patch 8f07b507b78ff94776f2cd49276eb116ed93d7f2 to versions prior to 2.8.1.

Exploit

Fix

Improper Resource Release

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92417

Affected Products

Open5Gs