CVE-2026-90707

Summary

A security flaw has been discovered in Open5GS up to 2.7.x. Affected is the function amf_nnrf_try_old_amf_discovery_fallback of the file src/amf/nnrf-handler.c of the component Old AMF Discovery Fallback. The manipulation of the argument discovery_option results in use after free. The attack may be performed from remote. The patch is identified as ddd683a35f8aaac2b7b9884a24cd53bddfc65238. Applying a patch is advised to resolve this issue.

Affected Software

VendorProductVersion RangeStatus
n/aOpen5GS2.0affected
n/aOpen5GS2.1affected
n/aOpen5GS2.2affected
n/aOpen5GS2.3affected
n/aOpen5GS2.4affected
n/aOpen5GS2.5affected
n/aOpen5GS2.6affected
n/aOpen5GS2.7affected

Weaknesses

  • CWE-416: Use After Free
  • CWE-119: Memory Corruption

References