Junglewise Threat Intelligence

CVE-2026-10114: Open5GS out-of-bounds write in Shared NF-profile Parser

CVE-2026-10114 · Severity: medium · CVSS 4.3 · Published 2026-05-30

Technologies: Open5GS. Vendors: Open5GS.

Executive brief

Open5GS is an open-source implementation of 5G and 4G mobile core networks. A vulnerability in how it processes network function profiles allows a remote attacker to crash critical network components, such as the Network Repository Function (NRF). This could lead to a denial of service, disrupting mobile network connectivity and operations.

Technical details

An out-of-bounds write vulnerability exists in Open5GS versions up to 2.7.7 within the 'handle_scp_info' function of 'lib/sbi/nnrf-handler.c'. The issue stems from the Shared NF-profile Parser failing to validate the number of entries in 'scpDomainInfoList' against the 'OGS_MAX_NUM_OF_SCP_DOMAIN' constant before copying them into a fixed-size array. A remote attacker with low privileges (capable of sending NF-profile data) can trigger a memory corruption, typically resulting in a segmentation fault (exit code 139) or stack-smashing termination. This affects multiple network functions including NRF, AMF, SMF, and others that utilize the shared SBI library. A patch is recommended to enforce bounds checking.

Affected products

  • Open5GS Open5GS up to 2.7.7

Timeline

  • 2026-04-22: disclosed: Issue reported on GitHub
  • 2026-05-30: advisory: NVD/VulDB publication

References

Related threats