PT-2026-41538 · Open5Gs · Open5Gs
Ziyulin
·
Published
2026-05-17
·
Updated
2026-05-18
·
CVE-2026-8746
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Open5GS versions prior to 2.7.8
Description
A use after free flaw exists in the NRF component within the
discover handler() function located in the /lib/sbi/nghttp2-server.c library. This issue allows a remote attacker to manipulate the system, potentially leading to a crash or unauthorized code execution. Use after free occurs when an application continues to use a pointer after it has been freed, which can corrupt memory.Recommendations
Update to a version newer than 2.7.7.
As a temporary workaround, restrict access to the NRF component to minimize the risk of exploitation.
Exploit
Fix
Use After Free
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open5Gs