Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Tommi Maekilae

Pesquisador deCyRC
#32390de 53,638
7.8CVSS total
Vulnerabilidades · 1
PT-2023-1375
7.8
2023-01-31
Open5Gs · Open5Gs Gtp · CVE-2023-23846
**Name of the Vulnerable Software and Affected Versions** Open5GS GTP versions prior to 2.4.13 Open5GS GTP versions prior to 2.5.7 **Description** The issue is related to insufficient length validation in the Open5GS GTP library, which can cause an infinite loop when parsing extension headers in GPRS tunneling protocol (GPTv1-U) messages. This occurs when a protocol payload has any extension header length set to zero, resulting in denial of service and excessive resource consumption. The affected process becomes immediately unresponsive. **Recommendations** For versions prior to 2.4.13, update to version 2.4.13 or later. For versions prior to 2.5.7, update to version 2.5.7 or later. As a temporary workaround, consider restricting the parsing of extension headers in GPTv1-U messages to prevent infinite loops until a patch is available.