PT-2026-45507 · Git+1 · Flexric
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
FlexRIC version 2.0.0
Description
A reachable assertion exists in the
e2ap recv sctp msg() function within src/lib/ep/e2ap ep.c. The function uses a fixed 32KB receive buffer and enforces an assertion on the return value of sctp recvmsg(). A remote unauthenticated attacker can cause a crash of the near-RT RIC, iApp, E2 Agent, or xApp process by sending a single SCTP message with a payload of 32,768 bytes or more, triggering a SIGABRT. This issue affects all four SCTP endpoint types on ports 36421 and 36422 and does not require a valid E2AP PDU. In Release builds (NDEBUG), the absence of the assertion can result in a signed-to-unsigned integer overflow and a potential out-of-bounds read.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flexric