ZeroHour

CVE-2026-37198

moderate

Integer Overflow DoS in Open5GS SMF via Crafted GTP Packets

CVSS 3.1
7.5 high
EPSS
<1%p38
Published
()
Modified
AI analysis

CVE-2026-37198 is an integer overflow (CWE-190) in the Session Management Function (SMF) component of Open5GS, the open-source 4G/5G core network, reported in version v2.7.6. It is triggered by sending a crafted GTP packet to the affected GTP handling path over the network, requiring no authentication and no user interaction. A successful attack causes a high-availability impact only: the SMF can crash or become unavailable, disrupting subscriber session management, with no confidentiality or integrity impact per the CVSS vector. Affected parties are operators and integrators running Open5GS, particularly deployments whose GTP interfaces are reachable beyond fully trusted radio/transport networks, such as lab, private-network, and small-operator setups. No exploitation in the wild, public proof-of-concept, or KEV listing is known; EPSS is 0.4% (38th percentile), indicating low near-term exploitation probability.

What to do: Upgrade Open5GS to a patched release as soon as one is published (check the project's GitHub releases/security advisories for a fix beyond v2.7.6). Until patched, restrict GTP traffic (typically UDP port 2152) with firewall/ACL rules to known eNodeB/gNB and SGW/UPF peers only, and monitor the SMF for crashes or restarts. Since the flaw is unauthenticated and availability-only, prioritize hosts whose GTP interface is reachable from untrusted or shared networks.

Affected
Open5GS (SMF component)v2.7.6 (version cited in the advisory; check project advisories for the full affected range)
Estimated exposure
moderatelikely on the order of thousands of Open5GS deployments (labs, private 4G/5G networks, small operators), with the internet-exposed subset plausibly in the… — Open5GS is a widely used open-source 4G/5G core with no central install telemetry, so this order-of-magnitude figure is inferred from deployment patterns (private networks, testbeds, small carriers) rather than measured counts; only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An integer overflow in the SMF component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted GTP packet.

Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.