Description
An integer overflow in the SMF component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted GTP packet.
Published: 2026-08-27
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow has been identified in the SMF component of Open5GS version 2.7.6. By sending a specially crafted GTP packet that manipulates an internal counter, an attacker can trigger a numeric overflow that destabilizes the SMF process, causing it to crash and leading to a denial of service. This flaw does not provide direct data exfiltration or code execution, but it compromises the availability of the 5G core network infrastructure.

Affected Systems

The vulnerability affects the SMF (Session Management Function) module within the Open5GS open-source 5G core platform, specifically published in release 2.7.6. Operators running this version of Open5GS without a mitigating patch or configuration hardening are exposed.

Risk and Exploitability

The EPSS score is not reported and the vulnerability is not listed in the CISA KEV catalog, but the fault allows a remote attacker to disrupt network services by sending malformed packets. Because the attack vector is network‑based, it can be executed from outside the infrastructure without prior authentication, and the impact is availability degradation that can affect all user equipment attached to the impacted SMF instance.

Generated by OpenCVE AI on August 28, 2026 at 05:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Open5GS to a version that eliminates the integer overflow bug, checking the project’s releases or contacting the maintainers for a fix
  • Configure network firewalls or IDS systems to drop or rate‑limit suspicious GTP packets that could trigger the overflow
  • Monitor SMF logs for repeated GTP packet anomalies and correlate with service restarts to detect ongoing exploitation attempts

Generated by OpenCVE AI on August 28, 2026 at 05:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Open5gs
Open5gs open5gs
Vendors & Products Open5gs
Open5gs open5gs

Fri, 28 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Open5GS SMF Causes DoS via Crafted GTP Packet
Weaknesses CWE-190

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description An integer overflow in the SMF component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted GTP packet.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-27T20:04:02.416Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-37198

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T20:17:43.563

Modified: 2026-08-27T20:17:43.563

Link: CVE-2026-37198

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T09:45:17Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound