Impact
In osmo-ggsn 1.14.0 the gtp_decode_pdp_ctx() function handles the GSN-Address sub‑field of a PDP context without performing a boundary check. This introduces an out‑of‑bounds write that corrupts adjacent memory, an instance of CWE‑787. The resulting memory corruption can alter program data or control flow, potentially enabling arbitrary code execution if an attacker controls the corrupted data.
Affected Systems
The vulnerability applies to the Osmocom osmo‑ggsn software. Only installations running version 1.14.0 are listed as affected; no other revisions are mentioned.
Risk and Exploitability
The EPSS score is <1%, and the CVSS score is 6.5, indicating moderate risk. The vulnerability is not listed in the KEV catalog, indicating no publicly confirmed exploits are known. The likely attack vector involves a specially crafted GTP packet containing an oversized GSN-Address field sent over the network to a device running the vulnerable ggsn. Exploitation would require the attacker to be able to influence GTP traffic to the target, which may be limited by network segmentation.
OpenCVE Enrichment