← Back to CVE List
CVE-2026-92417NVD
Vulnerability Summary
A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the library lib/pfcp/types.c of the component PFCP Handler. The manipulation results in null pointer dereference. The attack may be launched remotely. The patch is identified as 8f07b507b78ff94776f2cd49276eb116ed93d7f2. A patch should be applied to remediate this issue.
CVSS v4.0 Base Metrics — Score 7.1 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredLow
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 6.5 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityHigh
Affected & Patched Versions
- n/a Open5GS >= 2.0
- n/a Open5GS >= 2.1
- n/a Open5GS >= 2.2
- n/a Open5GS >= 2.3
- n/a Open5GS >= 2.4
- n/a Open5GS >= 2.5
- n/a Open5GS >= 2.6
- n/a Open5GS >= 2.7
- n/a Open5GS >= 2.8.0
Not provided by cveorg for this CVE.