Executive brief
Open5GS is a 5G network core infrastructure software that handles session management and packet routing. An integer overflow vulnerability in its SMF (Session Management Function) component allows remote attackers to crash the service by sending specially crafted GTP (GPRS Tunneling Protocol) packets, causing a denial of service to mobile network subscribers.
Technical details
An integer overflow exists in the SMF component of Open5GS v2.7.6 when processing GTP control messages, specifically in the handling of Bearer Context information elements. The vulnerability occurs due to insufficient validation of the number and structure of these IEs during packet parsing. An attacker can exploit this remotely by crafting a malicious GTP packet that triggers the integer overflow, leading to a crash of the SMF service. No authentication is required to send GTP packets to the network element. A fix is required from the Open5GS maintainers.
Affected products
- Open5GS Open5GS v2.7.6
Timeline
- 2026-05-12: disclosed
- 2026-08-27: advisory