Impact
A flaw in the Open5GS AMF component, located in src/amf/gmm-handler.c, allows an attacker to supply a crafted reg_type value that causes the process to crash, resulting in a denial of service. The weakness is a missing error check for a user‑supplied argument, formally identified as CWE‑404.
Affected Systems
The vulnerability exists in all Open5GS releases up to and including 2.7.6. The affected product is the AMF module of Open5GS; upgrading to version 2.7.7, which incorporates the commit ebc66942b6f8f1fab2d640e71cf4e9f1a423b426, resolves the issue.
Risk and Exploitability
The CVSS score of 5.3 represents moderate severity; no EPSS score is reported and the flaw is not listed in CISA’s KEV catalog. Exploitation can be performed remotely, and repeated attacks could repeatedly crash the AMF process, degrading availability for all users of the affected instance.
OpenCVE Enrichment