Git · Flexric · CVE-2026-37229
**Name of the Vulnerable Software and Affected Versions**
FlexRIC version 2.0.0
**Description**
A reachable assertion in the `e2ap create pdu()` function is triggered when ASN.1 PER (Packed Encoding Rules, a binary encoding format for ASN.1 data) decoding fails. A remote unauthenticated attacker can send a non-PER byte sequence over SCTP to the near-RT RIC on port 36421 or the iApp on port 36422, causing the process to crash via SIGABRT. This occurs before any protocol-level validation takes place and affects E2AP protocol versions v1.01, v2.03, and v3.01.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.