CVE-2026-75438

Open5GS · Open5GS

A buffer overflow vulnerability in the ogs_sbi_time_parse function of Open5GS v2.7.7 allows a remote, unauthenticated attacker to trigger a denial of service.

Executive summary

A buffer overflow vulnerability in Open5GS v2.7.7 permits a remote attacker to crash the application, leading to a denial of service.

Vulnerability

The vulnerability exists within the ogs_sbi_time_parse function. It allows an unauthenticated remote attacker to cause a buffer overflow, which results in a denial of service condition.

Business impact

A denial of service attack against core network software can lead to significant service outages and loss of availability for connected users. With a CVSS score of 7.5, this vulnerability represents a high risk to network stability and operational continuity.

Remediation

Immediate Action: Update Open5GS to a version containing the fix for this buffer overflow, specifically incorporating commit 7227b2f5b254160286798e058c189224360d99fc.

Proactive Monitoring: Monitor system logs for unexpected application crashes and spikes in traffic targeting the SBI interface.

Compensating Controls: Utilize network traffic filtering and rate limiting at the perimeter to inspect and drop malformed packets that might trigger the overflow in the affected function.

Exploitation status

Public Exploit Available: Yes (a published PoC exists, attributed to the linked GitHub repository 5GCVulDB)

Analyst recommendation

Given the availability of a proof-of-concept and the critical nature of the affected software, immediate patching is required. Organizations must verify their Open5GS version and apply the upstream fix to prevent potential service disruption.

More Open5GS CVEs

History

CVE Brief tracked this CVE 5 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.5 (3.1)
  4. Analyst report written
  5. Analyst report updated

Sources