Open5GS 2.8.0 及更早版本中存在一个堆越界读取漏洞,位于函数 中。该漏洞允许远程未认证的攻击者通过构造较短的 IE(信息元素)缓冲区,读取超出 IE 边界的数据。攻击者可以向 UPF(用户面功能)的 UDP 8805 端口发送设置了 DLPA(下行链路 PFCP 关联)和 DLBY(下行链路字节计数)标志的 PFCP 会话建立或修改请求,从而导致 UPF 崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108105 | 5.9 MEDIUM | Open5GS through 2.8.0 MME Reachable Assertion via GTPv1 SGSN Context Request |
| CVE-2026-108102 | 5.3 MEDIUM | Open5GS through 2.8.0 Heap Out-of-Bounds Read via PFCP Volume Measurement IE |
No comments yet