Junglewise Threat Intelligence

CVE-2026-7183: aligungr UERANSIM uncaught exception in Radio Link Simulation Layer

CVE-2026-7183 · Severity: medium · CVSS 5.3 · Published 2026-04-27

Executive brief

UERANSIM is an open-source simulator for 5G mobile phones and base stations used for testing 5G core networks. A vulnerability in its radio link simulation layer allows a remote attacker to crash the software by sending specially crafted messages. This results in a denial-of-service condition, disrupting 5G network testing and simulation activities.

Technical details

A vulnerability exists in the Radio Link Simulation Layer of UERANSIM up to version 3.2.7. The root cause is located in the rls::DecodeRlsMessage function within src/lib/rls/rls_pdu.cpp, where improper manipulation of the pduLength argument leads to an uncaught exception (CWE-248). A remote, unauthenticated attacker can exploit this over the network to cause the application to terminate unexpectedly. The issue has been addressed in version 3.2.8 through security hardening of the RLS layer.

Affected products

  • aligungr UERANSIM up to 3.2.7

Timeline

  • 2026-04-15: patched: Patch ca1a66fffe282767bb08618af9f848e3b68ea47b released
  • 2026-04-27: disclosed: Initial disclosure via VulDB/NVD

References