Impact
In osmo-iuh, a reachable assertion is triggered in the ranap_handle_co_dt() function when an arbitrarily sized NAS-PDU is processed. The assertion causes the process to crash, resulting in a remote denial of service. The vulnerability is exploitable by an attacker who can send a crafted NAS-PDU over the network; the impact is loss of availability for the affected service, while confidentiality and integrity remain unaffected.
Affected Systems
The issue exists in osmo-iuh versions 0.1.0 through 1.8.0. Systems running any of these releases are affected. The vulnerable component is the NAS Radio Access Protocol handling code shipped with the Osmocom osmo-iuh package.
Risk and Exploitability
The CVSS score is 7.5, and the EPSS score is < 1%, indicating that while the vulnerability is moderate to high in severity, the probability of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Because an attacker only needs to send a large or malformed NAS-PDU over the network, the attack vector is remote, similar to a typical denial-of-service over a network service. No OS patch or vendor‑specific workaround is mentioned beyond applying the provided patch or upgrading the package.
OpenCVE Enrichment