Junglewise Threat Intelligence

CVE-2026-30075: OpenAirInterface AUSF buffer overflow in UplinkNASTransport processing

CVE-2026-30075 · Severity: high · CVSS 7.5 · Published 2026-04-08

Executive brief

OpenAirInterface, an open-source software platform for 5G wireless networks, contains a flaw in how it handles mobile device authentication. An attacker can send a specially crafted, oversized authentication message that causes the core network's authentication service to crash. This results in a denial-of-service, preventing new users from registering or connecting to the cellular network.

Technical details

A classic buffer overflow (CWE-120) exists in OpenAirInterface Version 2.2.0 within the Authentication Server Function (AUSF) component. The vulnerability is triggered when the Access and Mobility Management Function (AMF) decodes an UplinkNASTransport message containing a NAS PDU with an oversized authentication response (e.g., 100 bytes) and passes it to the AUSF for verification. The AUSF fails to perform adequate bounds checking on the 'resStar' field, leading to a memory corruption and service crash. An attacker can exploit this over the network without authentication to cause a Denial of Service (DoS), preventing legitimate users from completing the registration and verification process. At the time of reporting, the issue was identified in the oai-cn5g-ausf repository.

Affected products

  • OpenAirInterface OpenAirInterface AUSF 2.2.0
  • OpenAirInterface OpenAirInterface AMF 2.2.0

Timeline

  • 2026-04-08: disclosed: Initial disclosure of CVE-2026-30075
  • 2026-04-08: advisory

References

Related threats