PT-2026-31331 · Unknown · Openairinterface

Published

2026-04-08

·

Updated

2026-04-13

·

CVE-2026-30075

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenAirInterface version 2.2.0
Description OpenAirInterface version 2.2.0 contains a buffer overflow issue when processing an UplinkNASTransport with an Authentication Response containing an oversized NAS PDU (for example, 100 bytes). The response is decoded by the AMF and passed to the AUSF component for verification. The AUSF component crashes when receiving this oversized response, potentially leading to a denial of service (DoS) and preventing users from completing registration and verification.
Recommendations Update to a newer version of OpenAirInterface that addresses this issue. As a temporary workaround, consider filtering or limiting the size of Authentication Responses received by the AUSF component.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-30075

Affected Products

Openairinterface