CVE-2026-30078

7.5

OpenAirInterface · OAI-CN5G-AMF

OpenAirInterface V2.2.0 AMF is vulnerable to a denial of service condition when processing malformed NGAP messages containing invalid procedure codes or PDU types.

Executive summary

A critical denial of service vulnerability in OpenAirInterface V2.2.0 allows unauthenticated remote attackers to crash the AMF component via malformed network packets.

Vulnerability

The vulnerability exists in the AMF component, which fails to properly validate the structure of incoming NGAP messages. An unauthenticated attacker can trigger a crash by sending messages with invalid procedure codes or PDU types, such as providing a successfulOutcome where an InitiatingMessage is expected.

Business impact

The exploitation of this flaw results in a complete denial of service for the Access and Mobility Management Function (AMF), which is a critical control plane element in 5G core networks. Given the CVSS score of 7.5, the impact is significant because it allows remote, unauthenticated disruption of network connectivity and session management, potentially leading to widespread service outages.

Remediation

Immediate Action: Monitor the official OpenAirInterface GitLab repository for the release of a patched version of the OAI-CN5G-AMF component and apply it as soon as it becomes available.

Proactive Monitoring: Review system logs for unexpected AMF service restarts or error messages related to NGAP message parsing failures.

Compensating Controls: Implement strict network ingress filtering to ensure only authorized traffic from expected gNodeB components reaches the AMF, reducing the attack surface for malformed packet injection.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability presents a clear risk to the stability of 5G core network infrastructure. Administrators should prioritize the deployment of the forthcoming security update for the AMF component to prevent potential service disruption by remote, unauthenticated actors.

More OpenAirInterface CVEs

Sources