CVE-2026-92417
nicheNull pointer dereference in Open5GS PFCP handler enables remote DoS (up to 2.8.0)
Open5GS up to and including 2.8.0 contains a null pointer dereference (CWE-476) in ogs_pfcp_parse_volume_measurement in lib/pfcp/types.c, part of the PFCP message handler used by its 4G/5G core network functions. An attacker who can send crafted PFCP traffic to a vulnerable SMF or UPF can trigger the flaw remotely, causing the affected process to crash. Per the CVSS 4.0 score (7.1 High), the impact is high availability loss with no confidentiality or integrity impact, so the practical outcome is denial of service of core network elements. Any operator running Open5GS 2.8.0 or earlier is affected, particularly deployments where the PFCP endpoint (typically UDP 8805) is reachable from untrusted networks. No public proof-of-concept is known and the flaw is not listed in CISA KEV, so exploitation has not been confirmed.
What to do: Upgrade Open5GS to a release that includes the fix commit 8f07b507b78ff94776f2cd49276eb116ed93d7f2, or apply that commit to a 2.8.0 build. Until patched, firewall PFCP (UDP 8805) so only trusted SMF/UPF peers can reach it and restrict N4 interface exposure to management networks. Monitor SMF/UPF processes for unexplained crashes or restarts, which could indicate probing against this flaw.
| Open5GS (PFCP handler, lib/pfcp/types.c) | up to and including 2.8.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the library lib/pfcp/types.c of the component PFCP Handler. The manipulation results in null pointer dereference. The attack may be launched remotely. The patch is identified as 8f07b507b78ff94776f2cd49276eb116ed93d7f2. A patch should be applied to remediate this issue.
- Weakness
- CWE-404, CWE-476
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.