Impact
Open5GS is a software implementation for 5G core networks. A flaw in the GTP‑U receive path, specifically the function ogs_pfcp_xact_local_create in src/upf/gtp-path.c, allows an attacker to cause uncontrolled allocation of resources. This can lead to exhaustion of memory or other system resources, potentially causing the UPF module to crash or become unusable. The weakness corresponds to CWE‑400 and CWE‑770, indicating unbounded resource consumption and failure to handle memory allocation errors.
Affected Systems
Affected vendor is Open5GS (cpe:2.3:a:open5gs:open5gs). The issue exists in all releases up to and including version 2.7.7. Any user running 2.7.7 or earlier is vulnerable. The affected component is the GTP‑U Receive Path within the UPF service of the Open5GS stack.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity; the EPSS score is not available, but the vulnerability has been made public and the exploit is known, meaning that remote attackers can target exposed UPF instances. The flaw is not yet listed in the CISA KEV catalogue, but the combination of medium severity and publicly available exploitation code elevates the risk for environments with a 5G core exposed to untrusted traffic. Attackers can leverage simple crafted GTP‑U packets to spike resource usage and trigger denial of service.
OpenCVE Enrichment