CVE-2026-90707

8.3

Open5GS · Open5GS

A use after free vulnerability exists in the Open5GS AMF component due to improper handling of the discovery_option argument in the Old AMF Discovery Fallback function.

Executive summary

A remote use after free vulnerability in Open5GS versions 2.0 through 2.7 poses a significant risk to the integrity and availability of core 5G network functions.

Vulnerability

This is a use after free memory corruption flaw located in the amf_nnrf_try_old_amf_discovery_fallback function within src/amf/nnrf-handler.c. The vulnerability is exploitable by an unauthenticated remote attacker through the manipulation of the discovery_option argument.

Business impact

The vulnerability carries a CVSS score of 8.3, indicating a high level of severity. Successful exploitation could lead to arbitrary code execution, system crashes, or denial of service within the mobile core network, potentially resulting in widespread telecommunications outages and unauthorized access to sensitive signaling traffic.

Remediation

Immediate Action: Administrators must apply the upstream fix identified by commit hash ddd683a35f8aaac2b7b9884a24cd53bddfc65238 or upgrade to the latest stable release of Open5GS where this patch is integrated.

Proactive Monitoring: Monitor network infrastructure logs for abnormal process behavior, segmentation faults, or frequent restarts of the AMF service, which may indicate attempted exploitation.

Compensating Controls: Implement strict network segmentation and firewall rules to limit access to the AMF interface, ensuring only authorized network elements can interact with the affected service.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the critical nature of the affected software, organizations deploying Open5GS must prioritize the application of the provided patch. Failure to remediate this flaw exposes core network infrastructure to potential remote compromise and service disruption; therefore, testing and deployment of the fix should be scheduled immediately.

More Open5GS CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by centauruszzz (VulDB User), per the CVE Program record.