Description
A vulnerability was found in aligungr UERANSIM up to 3.3.0. This affects the function ULInformationTransfer of the file src/gnb/rrc/handler.cpp of the component nr-gnb. Performing a manipulation of the argument dedicatedNASMessage results in memory corruption. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Memory corruption leading to potential remote code execution
Action: Patch
AI Analysis

Impact

A memory corruption flaw occurs in the ULInformationTransfer function within UERANSIM's nr-gnb component. Manipulating the dedicatedNASMessage argument can overwrite arbitrary memory locations, which may allow an attacker to execute arbitrary code, crash the service or otherwise disrupt the network function. The vulnerability is directly exploitable and has been publicly demonstrated, indicating a clear risk to confidentiality, integrity and availability of the affected system.

Affected Systems

Versions of aligungr UERANSIM up to 3.3.0 are affected, specifically the handler.cpp file handling ULInformationTransfer in the nr-gnb component. The flaw is listed in multiple public advisories and vulnerability databases, and it has been reported to the vendor without response.

Risk and Exploitability

The attack can be launched remotely, and an exploit is available online, meaning an adversary does not need privileged access. The CVSS score of 6.9 shows moderate to high severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is memory corruption (CWE‑119), it can allow arbitrary code execution if the attacker can influence the memory state during the vulnerable function. The lack of a published patch and the presence of a public exploit increase the risk profile for exposed UERANSIM installations.

Generated by OpenCVE AI on September 28, 2026 at 01:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • If a newer, patched version of UERANSIM is available, upgrade to that release immediately.
  • If no patch is available, isolate the UERANSIM GNB component in a separate network segment and restrict inbound traffic to only trusted peers.
  • Enable monitoring of ULInformationTransfer calls and anomalous memory usage patterns to detect attempted exploitation.

Generated by OpenCVE AI on September 28, 2026 at 01:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in aligungr UERANSIM up to 3.3.0. This affects the function ULInformationTransfer of the file src/gnb/rrc/handler.cpp of the component nr-gnb. Performing a manipulation of the argument dedicatedNASMessage results in memory corruption. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title aligungr UERANSIM nr-gnb handler.cpp ULInformationTransfer memory corruption
First Time appeared Aligungr
Aligungr ueransim
Weaknesses CWE-119
CPEs cpe:2.3:a:aligungr:ueransim:*:*:*:*:*:*:*:*
Vendors & Products Aligungr
Aligungr ueransim
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Aligungr Ueransim
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T00:30:09.114Z

Reserved: 2026-09-27T08:11:02.503Z

Link: CVE-2026-100892

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T01:16:28.583

Modified: 2026-09-28T01:16:28.583

Link: CVE-2026-100892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T02:00:18Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer