Open5Gs · Open5Gs · CVE-2024-57519
**Name of the Vulnerable Software and Affected Versions**
Open5GS version 2.7.2
**Description**
The issue in Open5GS is related to the `ogs dbi auth info()` function in the `lib/dbi/subscription.c` file, which is associated with unlimited resource allocation. This can be exploited by a remote attacker to cause a denial of service.
**Recommendations**
For Open5GS version 2.7.2, consider disabling the `ogs dbi auth info()` function as a temporary workaround until a patch is available. Restrict access to the `lib/dbi/subscription.c` file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.