Executive brief
Open5GS is an open-source 5G core network implementation used by telecom operators and testing environments. A heap-based buffer overflow in the S6a authentication handler allows an attacker to send a specially crafted network message with a malformed Visited-PLMN-Id field, potentially causing service crashes or remote code execution in the home subscriber server (HSS).
Technical details
A heap-based buffer overflow exists in the hss_ogs_diam_s6a_air_cb function in src/hss/hss-s6a-path.c, which processes Diameter Authentication-Information-Request (AIR) messages on the S6a interface. The vulnerability occurs because the function does not properly validate the length of the Visited-PLMN-Id AVP (Attribute-Value Pair) before using it in a memory operation, allowing an attacker to write beyond allocated buffer bounds. An attacker with network access to the S6a interface can remotely trigger this overflow by sending a malicious AIR message. The impact includes denial of service and potential code execution with HSS privileges. A patch (commit a9c82ee0b590d76a581b0580cb46b598984e2392) that adds length validation for the Visited-PLMN-Id field has been released.
Affected products
- Open5GS Open5GS 2.8.0
Timeline
- 2026-08-24: disclosed
- 2026-08-24: patched: Patch commit a9c82ee0b590d76a581b0580cb46b598984e2392