PT-2026-8283 · Open5Gs · Open5Gs

Linziyu

·

Published

2026-02-15

·

Updated

2026-02-16

·

CVE-2026-2521

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open5GS versions prior to 2.7.7
Description A flaw exists in Open5GS up to version 2.7.6 related to the sgwc s5c handle create session response function within the SGW-C component. A manipulation can lead to memory corruption and may be performed remotely. The exploit has been publicly released. The project was notified of the issue but has not yet responded.
Recommendations Update to version 2.7.7 or later. As a temporary workaround, consider restricting access to the sgwc s5c handle create session response function until a patch is available.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-2521

Affected Products

Open5Gs