Executive brief
Open5GS is an open-source implementation of 5G and 4G mobile core networks. A vulnerability in how it processes network function profiles allows a remote attacker to crash critical network components, such as the Network Repository Function (NRF). This could lead to a denial of service, disrupting mobile network connectivity and operations.
Technical details
An out-of-bounds write vulnerability exists in Open5GS versions up to 2.7.7 within the 'handle_scp_info' function of 'lib/sbi/nnrf-handler.c'. The issue stems from the Shared NF-profile Parser failing to validate the number of entries in 'scpDomainInfoList' against the 'OGS_MAX_NUM_OF_SCP_DOMAIN' constant before copying them into a fixed-size array. A remote attacker with low privileges (capable of sending NF-profile data) can trigger a memory corruption, typically resulting in a segmentation fault (exit code 139) or stack-smashing termination. This affects multiple network functions including NRF, AMF, SMF, and others that utilize the shared SBI library. A patch is recommended to enforce bounds checking.
Affected products
- Open5GS Open5GS up to 2.7.7
Timeline
- 2026-04-22: disclosed: Issue reported on GitHub
- 2026-05-30: advisory: NVD/VulDB publication