Junglewise Threat Intelligence

CVE-2026-37226: EURECOM FlexRIC null pointer dereference in iApp subscription handling

CVE-2026-37226 · Severity: info · CVSS 8.6 · Published 2026-06-01

Technologies: EURECOM FlexRIC. Vendors: EURECOM.

Executive brief

FlexRIC, a controller used in Open RAN cellular networks, is vulnerable to a remote crash. An unauthenticated attacker can send a specially crafted subscription request to the system, causing the iApp process to stop functioning. This results in a denial of service, disrupting the management and intelligence operations of the radio access network.

Technical details

A NULL pointer dereference exists in FlexRIC v2.0.0 within the `find_map_e2_node_sad()` function in `src/ric/map_e2_node_sockaddr.c`. When the iApp receives an `E42_RIC_SUBSCRIPTION_REQUEST` referencing a non-existent `global_e2_node_id`, the lookup function returns NULL. In debug builds, this triggers an `assert()` (SIGABRT), while in release builds, the pointer is dereferenced, leading to a segmentation fault (SIGSEGV). A remote, unauthenticated attacker can exploit this by sending a malicious request to SCTP port 36422, resulting in a denial of service of the iApp and co-located RIC services.

Affected products

  • EURECOM FlexRIC v2.0.0 through commit 6a595d8b

Timeline

  • 2026-06-01: advisory: NVD and researcher advisory published

References

Related threats