Junglewise Threat Intelligence

CVE-2026-8252: Open5GS SMF null pointer dereference in PDU session handling

CVE-2026-8252 · Severity: medium · CVSS 4.3 · Published 2026-05-11

Technologies: Open5GS. Vendors: Open5GS.

Executive brief

Open5GS is an open-source implementation of 5G and LTE mobile core networks. A flaw in how the Session Management Function (SMF) handles specific session requests allows a remote attacker to crash the service. This results in a denial-of-service condition, potentially disrupting mobile connectivity for users on the affected network.

Technical details

A null pointer dereference exists in the Open5GS Session Management Function (SMF) within the smf_nsmf_handle_create_data_in_hsmf function. The vulnerability is triggered when a 'POST /nsmf-pdusession/v1/pdu-sessions' request omits the 'vcnTunnelInfo' field. While the code attempts to validate the presence of this field, the error logging logic immediately dereferences the null pointer when the field is missing, leading to a process crash (SIGSEGV). An attacker with network access to the SMF SBI interface can exploit this to cause a denial of service. As of the advisory date, the project has been notified via an issue report but a formal patch has not been confirmed.

Affected products

  • Open5GS Open5GS up to 2.7.7

Timeline

  • 2026-04-20: disclosed: Issue reported on GitHub repository
  • 2026-05-11: advisory: VulDB and NVD publication

References

Related threats