Junglewise Threat Intelligence

CVE-2026-10565: Open5GS race condition in AMF security mode handling

CVE-2026-10565 · Severity: low · CVSS 3.1 · Published 2026-06-02

Technologies: Open5GS. Vendors: Open5GS.

Executive brief

Open5GS is an open-source implementation of 5G and LTE mobile core networks. A flaw in how the system handles security procedures during mobile device handovers can lead to a race condition. If exploited, this could cause a mismatch in security keys between the mobile device and the network, potentially leading to a localized denial of service or connection instability for affected users.

Technical details

A race condition exists in the Access and Mobility Management Function (AMF) of Open5GS up to version 2.7.6. The vulnerability is located in the gmm_state_security_mode function within src/amf/gmm-sm.c. The root cause is a failure to enforce concurrent security procedure rules defined in 3GPP TS 33.501 §6.9.5.1, specifically regarding the serialization of NAS Security Mode Command (SMC) and N2 handover procedures. An attacker can trigger this by initiating a re-registration while an N2 handover is ongoing, leading to a mismatch of the KgNB key between the User Equipment (UE) and the target gNodeB. This results in a loss of connectivity (Availability impact). While the attack can be initiated remotely, it requires specific timing and network conditions, resulting in high attack complexity.

Affected products

  • Open5GS Open5GS up to 2.7.6

Timeline

  • 2026-04-27: disclosed: Issue reported on GitHub
  • 2026-06-02: advisory: VulDB and NVD publication

References

Related threats