CVE-2026-92417

Summary

A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the library lib/pfcp/types.c of the component PFCP Handler. The manipulation results in null pointer dereference. The attack may be launched remotely. The patch is identified as 8f07b507b78ff94776f2cd49276eb116ed93d7f2. A patch should be applied to remediate this issue.

Affected Software

VendorProductVersion RangeStatus
n/aOpen5GS2.0affected
n/aOpen5GS2.1affected
n/aOpen5GS2.2affected
n/aOpen5GS2.3affected
n/aOpen5GS2.4affected
n/aOpen5GS2.5affected
n/aOpen5GS2.6affected
n/aOpen5GS2.7affected
n/aOpen5GS2.8.0affected

Weaknesses

  • CWE-476: NULL Pointer Dereference
  • CWE-404: Denial of Service

References