Description
In osmo-ggsn 1.14.0 an out of bounds write issue was found in the gtp_decode_pdp_ctx() function through the PDP context GSN-Address sub-field, leading to memory corruption.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption
Action: Patch Now
AI Analysis

Impact

In osmo-ggsn 1.14.0 the gtp_decode_pdp_ctx() function handles the GSN-Address sub‑field of a PDP context without performing a boundary check. This introduces an out‑of‑bounds write that corrupts adjacent memory, an instance of CWE‑787. The resulting memory corruption can alter program data or control flow, potentially enabling arbitrary code execution if an attacker controls the corrupted data.

Affected Systems

The vulnerability applies to the Osmocom osmo‑ggsn software. Only installations running version 1.14.0 are listed as affected; no other revisions are mentioned.

Risk and Exploitability

The EPSS score is <1%, and the CVSS score is 6.5, indicating moderate risk. The vulnerability is not listed in the KEV catalog, indicating no publicly confirmed exploits are known. The likely attack vector involves a specially crafted GTP packet containing an oversized GSN-Address field sent over the network to a device running the vulnerable ggsn. Exploitation would require the attacker to be able to influence GTP traffic to the target, which may be limited by network segmentation.

Generated by OpenCVE AI on September 21, 2026 at 20:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade osmo-ggsn to the most recent release that includes the fix for the out‑of‑bounds write.
  • If an upgrade cannot be performed immediately, enforce strict validation of the GSN-Address field length in incoming GTP packets to prevent the buffer overflow.
  • Restrict GTP traffic to trusted peers and block malformed or oversized GTP packets using firewall or ACL rules.

Generated by OpenCVE AI on September 21, 2026 at 20:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Osmocom
Osmocom osmo-ggsn
Vendors & Products Osmocom
Osmocom osmo-ggsn

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description In osmo-ggsn 1.14.0 an out of bounds write issue was found in the gtp_decode_pdp_ctx() function through the PDP context GSN-Address sub-field, leading to memory corruption.
Title Out of bounds write in PDP ctx GSN-Address decode
Weaknesses CWE-787
References

Subscriptions

Osmocom Osmo-ggsn
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat-cnalr

Published:

Updated: 2026-09-21T18:18:18.391Z

Reserved: 2026-08-18T14:04:08.775Z

Link: CVE-2026-75892

cve-icon Vulnrichment

Updated: 2026-09-21T18:18:11.129Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T19:16:45.747

Modified: 2026-09-21T19:17:09.733

Link: CVE-2026-75892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T20:45:17Z

Weaknesses