CVE-2026-75894

Osmocom · osmo-iuh

A reachable assertion in the ranap_handle_co_dt function of osmo-iuh allows unauthenticated remote attackers to trigger a process crash via a malformed NAS-PDU, resulting in a denial of service.

Executive summary

The Osmocom osmo-iuh software is vulnerable to a remote denial of service attack that can crash the process due to an unchecked assertion.

Vulnerability

This vulnerability is a reachable assertion (CWE-617) within the ranap_handle_co_dt function. An unauthenticated attacker can exploit this by sending an arbitrarily sized NAS-PDU to the affected service, triggering an assertion failure that forces the application to terminate.

Business impact

The successful exploitation of this vulnerability results in a complete denial of service for the affected infrastructure. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to service availability, potentially disrupting communication networks that rely on the osmo-iuh component.

Remediation

Immediate Action: Update the Osmocom osmo-iuh software to version 1.8.0 or later to include the necessary assertion fix.

Proactive Monitoring: Monitor system logs for unexpected process terminations or frequent service restarts associated with the osmo-iuh daemon.

Compensating Controls: Implement network-level filtering to restrict access to the affected service port, ensuring that only authorized traffic can reach the RANAP handling functions.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing osmo-iuh should prioritize the update to version 1.8.0 to eliminate the risk of remote service disruption. Given the ease of exploitation, failure to patch may lead to avoidable downtime in network environments.

History

CVE Brief tracked this CVE 3 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.5 (3.1) from cvelistV5
  4. Analyst report written

Sources

Originally found and disclosed by Nikolas Null "n0k0" - Security Researcher at mnemonic, per the CVE Program record.