PT-2026-41538 · Open5Gs · Open5Gs
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Open5GS versions prior to 2.7.8
Description
A use after free flaw exists in the NRF component within the
discover handler() function located in the /lib/sbi/nghttp2-server.c library. This issue allows a remote attacker to manipulate the system, potentially leading to a crash or unauthorized code execution. Use after free occurs when an application continues to use a pointer after it has been freed, which can corrupt memory.Recommendations
Update to a version newer than 2.7.7.
As a temporary workaround, restrict access to the NRF component to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open5Gs