Open5GS 2.8.0 及之前版本中,lib/pfcp/types.c 文件中的 ogs_pfcp_parse_volume_measurement() 函数存在堆缓冲区越界读取漏洞。该漏洞允许远程未认证攻击者读取超出指示元素(IE)缓冲区的边界数据。攻击者可向 SMF 通过 UDP 端口 8805 发送 PFCP Session Report Request 消息,并附带一个长度较短且所有标志位均置位的 Volume Measurement IE,从而最多可读取 48 字节的数据,并可能导致 SMF 崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108105 | 5.9 MEDIUM | Open5GS through 2.8.0 MME Reachable Assertion via GTPv1 SGSN Context Request |
| CVE-2026-108103 | 5.3 MEDIUM | Open5GS through 2.8.0 Heap Out-of-Bounds Read via PFCP Dropped DL Traffic Threshold IE |
No comments yet