CVE-2026-37198

Open5GS · Open5GS

An integer overflow vulnerability in the SMF component of Open5GS v2.7.6 allows unauthenticated remote attackers to cause a Denial of Service via a crafted GTP packet.

Executive summary

A critical integer overflow vulnerability in Open5GS allows unauthenticated remote attackers to crash the Session Management Function, resulting in a total Denial of Service.

Vulnerability

The vulnerability is an integer overflow located within the SMF component of the Open5GS core network software. It can be triggered by an unauthenticated remote attacker who sends a specially crafted GTP packet to the target system.

Business impact

The successful exploitation of this flaw results in a complete Denial of Service for the affected session management functions. Given the CVSS score of 7.5, this high severity vulnerability poses a significant risk to network availability, which could lead to widespread service disruption, loss of connectivity for downstream users, and potential operational downtime for telecommunications or private 5G infrastructure.

Remediation

Immediate Action: Review the Open5GS official repository and tracking issues for the release of a security patch, and apply the update to the SMF component immediately upon availability.

Proactive Monitoring: Monitor network traffic for malformed or unusually large GTP packets directed toward the SMF interface, and review system logs for crashes or unexpected service restarts.

Compensating Controls: Implement network level filtering or stateful inspection to drop non-compliant or malformed GTP packets before they reach the core network infrastructure.

Exploitation status

Public Exploit Available: Yes — a public proof of concept is available via the researcher write-up linked in the CVE references.

Analyst recommendation

The risk posed by this vulnerability is significant due to its potential to disrupt core network services without requiring authentication. Organizations deploying Open5GS should prioritize tracking the vendor repository for a fix and implement strict packet validation at the network perimeter to mitigate the risk of denial of service attacks until the software can be updated.

More Open5GS CVEs

Sources