Impact
Open5GS version 2.7.1 and earlier contain a stack‑based buffer overflow in hss_ogs_diam_s6a_ulr_cb, the Diameter S6a interface callback. By manipulating the os.len argument in a Diameter message, an attacker can trigger the overflow, breaking the stack and potentially executing arbitrary code on the host. The flaw maps to CWE‑119 and CWE‑121 and would allow a remote attacker to compromise confidentiality, integrity, and availability of the HSS.
Affected Systems
The affected vendor is Open5GS and the vulnerable component is the Diameter S6a interface, specifically src/hss/hss‑s6a‑path.c. All releases up to and including 2.7.1 are affected; the bug is fixed in release 2.7.2.
Risk and Exploitability
The CVSS score of 5.3 places the vulnerability at moderate severity. An EPSS score below 1% indicates that exploitation is unlikely, but a public exploit exists and the flaw is remotely reachable. The vulnerability is not listed in the CISA KEV catalog. Because attackers can trigger the overflow with a crafted Diameter request, the practical risk remains significant and the flaw should be patched as soon as possible.
OpenCVE Enrichment