ZeroHour

CVE-2026-92417

niche

Null pointer dereference in Open5GS PFCP handler enables remote DoS (up to 2.8.0)

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

Open5GS up to and including 2.8.0 contains a null pointer dereference (CWE-476) in ogs_pfcp_parse_volume_measurement in lib/pfcp/types.c, part of the PFCP message handler used by its 4G/5G core network functions. An attacker who can send crafted PFCP traffic to a vulnerable SMF or UPF can trigger the flaw remotely, causing the affected process to crash. Per the CVSS 4.0 score (7.1 High), the impact is high availability loss with no confidentiality or integrity impact, so the practical outcome is denial of service of core network elements. Any operator running Open5GS 2.8.0 or earlier is affected, particularly deployments where the PFCP endpoint (typically UDP 8805) is reachable from untrusted networks. No public proof-of-concept is known and the flaw is not listed in CISA KEV, so exploitation has not been confirmed.

What to do: Upgrade Open5GS to a release that includes the fix commit 8f07b507b78ff94776f2cd49276eb116ed93d7f2, or apply that commit to a 2.8.0 build. Until patched, firewall PFCP (UDP 8805) so only trusted SMF/UPF peers can reach it and restrict N4 interface exposure to management networks. Monitor SMF/UPF processes for unexplained crashes or restarts, which could indicate probing against this flaw.

Affected
Open5GS (PFCP handler, lib/pfcp/types.c)up to and including 2.8.0
Estimated exposure
nichelikely on the order of thousands of deployments worldwide (private 5G/EPC networks, labs and research testbeds); exact count unknown — Open5GS is an open-source 4G/5G core used mainly in private networks, testbeds and small-scale deployments rather than carrier-grade networks, and only a limited number of PFCP endpoints are typically visible in public internet scans, so a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the library lib/pfcp/types.c of the component PFCP Handler. The manipulation results in null pointer dereference. The attack may be launched remotely. The patch is identified as 8f07b507b78ff94776f2cd49276eb116ed93d7f2. A patch should be applied to remediate this issue.

Weakness
CWE-404, CWE-476
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.