在 Open5GS 2.7.7 及更早版本中发现了一个安全漏洞。受影响的是 文件中 N1-N2 消息处理器组件里的函数 。通过对参数 进行操纵,可引发服务拒绝(DoS)问题。该攻击可远程发起。利用该漏洞的工具/方法已公开,可用于实施攻击。建议升级至 2.8.0 版本以修复此问题。补丁编号为 abf8a836564b966b5141110fc25ed413c4f17522。建议升级受影响的组件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Open5GS | 2.7.0 |
cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82556 | 6.3 MEDIUM | Forgejo Repository Migration is_migrate_allowed.go net.LookupIP server-side request forger |
| CVE-2026-82590 | 4.3 MEDIUM | Open5GS SMF nudm-handler.c smf_nudm_sdm_handle_get assertion |
| CVE-2026-82588 | 4.3 MEDIUM | Open5GS Transfer Endpoint namf-handler.c null pointer dereference |
| CVE-2026-82587 | 4.3 MEDIUM | Open5GS AMF namf-handler.c amf_namf_comm_decode_ue_mm_context_list memory corruption |
No comments yet