Vulnerability Title: Open5GS SGWC v2.7.6 Denial of Service Description: Open5GS SGW-C crashes when processing a GTPv2 Create Session Request with a malformed Bearer QoS IE within the "Bearer Contexts to be Created" grouped IE. The SGW-C handler passes the Bearer QoS IE to the library function without validating the IE length, which results in a hard assertion being triggered if the length is incorrect, causing an immediate process abort. Affected Software: Open5GS SGWC v2.7.6 Source: https://github.com/open5gs/open5gs/issues/4217 User: LinZiyu (UID 94035) Submission Date: December 31, 2025 Moderation Date: January 1, 2026 Status: Accepted VulDB Entry: 239340 (Open5GS up to 2.7.6 Bearer QoS IE Length lib/gtp/v2/types.c ogs_gtp2_parse_bearer_qos denial of service) Points: 20