PT-2026-8294 · Open5Gs · Open5Gs

Linziyu

·

Published

2026-02-15

·

Updated

2026-03-19

·

CVE-2026-2523

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Open5GS versions prior to 2.7.7
Description An issue exists in Open5GS up to version 2.7.6 related to the smf gn handle create pdp context request function within the SMF component, specifically in the file /src/smf/gn-handler.c. The manipulation of this function results in a reachable assertion. The attack can be launched remotely. The exploit is publicly available.
Recommendations Update Open5GS to version 2.7.7 or later. As a temporary workaround, consider restricting access to the smf gn handle create pdp context request function until a patch is available.

Exploit

Fix

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02015
CVE-2026-2523

Affected Products

Open5Gs