Description
In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash and remote denial of service.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

In osmo-iuh, a reachable assertion is triggered in the ranap_handle_co_dt() function when an arbitrarily sized NAS-PDU is processed. The assertion causes the process to crash, resulting in a remote denial of service. The vulnerability is exploitable by an attacker who can send a crafted NAS-PDU over the network; the impact is loss of availability for the affected service, while confidentiality and integrity remain unaffected.

Affected Systems

The issue exists in osmo-iuh versions 0.1.0 through 1.8.0. Systems running any of these releases are affected. The vulnerable component is the NAS Radio Access Protocol handling code shipped with the Osmocom osmo-iuh package.

Risk and Exploitability

The CVSS score is 7.5, and the EPSS score is < 1%, indicating that while the vulnerability is moderate to high in severity, the probability of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Because an attacker only needs to send a large or malformed NAS-PDU over the network, the attack vector is remote, similar to a typical denial-of-service over a network service. No OS patch or vendor‑specific workaround is mentioned beyond applying the provided patch or upgrading the package.

Generated by OpenCVE AI on September 21, 2026 at 21:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade osmo-iuh to a release newer than 1.8.0, if available.
  • If a newer release is not available, apply the vendor‑provided patch commit f06967126f486bcb185ccf3d1a8f9bc02c4da1f6 or rebuild the package from a source tree that includes the fix.
  • Implement network filtering or rate limiting to restrict oversized NAS-PDU traffic while remediation is pursued.

Generated by OpenCVE AI on September 21, 2026 at 21:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Osmocom
Osmocom osmo-iuh
Vendors & Products Osmocom
Osmocom osmo-iuh

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash and remote denial of service.
Title Reachable assertion at ranap_handle_co_dt()
Weaknesses CWE-617
References

Subscriptions

Osmocom Osmo-iuh
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat-cnalr

Published:

Updated: 2026-09-21T18:26:10.848Z

Reserved: 2026-08-18T14:04:08.775Z

Link: CVE-2026-75894

cve-icon Vulnrichment

Updated: 2026-09-21T18:25:22.315Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T19:16:45.967

Modified: 2026-09-21T19:17:10.070

Link: CVE-2026-75894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T21:15:14Z

Weaknesses