PT-2026-93893 · Git · Open5Gs
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X |
Name of the Vulnerable Software and Affected Versions
Open5GS versions prior to 2.8.1
Description
A remote attack can cause a null pointer dereference in the PFCP Handler component. This occurs within the
ogs pfcp parse volume measurement() function located in the lib/pfcp/types.c library. A null pointer dereference is a condition where a program attempts to read or write to a memory address that is null, typically leading to a system crash.Recommendations
Apply patch 8f07b507b78ff94776f2cd49276eb116ed93d7f2 to versions prior to 2.8.1.
Exploit
Fix
Improper Resource Release
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open5Gs