Description
A security flaw has been discovered in Open5GS up to 2.7.x. Affected is the function amf_nnrf_try_old_amf_discovery_fallback of the file src/amf/nnrf-handler.c of the component Old AMF Discovery Fallback. The manipulation of the argument discovery_option results in use after free. The attack may be performed from remote. The patch is identified as ddd683a35f8aaac2b7b9884a24cd53bddfc65238. Applying a patch is advised to resolve this issue.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote use‑after‑free memory corruption
Action: Apply Patch
AI Analysis

Impact

In Open5GS versions up to 2.7.x the function amf_nnrf_try_old_amf_discovery_fallback in nnrf-handler.c contains a use‑after‑free flaw triggered by manipulation of the discovery_option argument. An attacker who can send a crafted request to the AMF service can cause memory corruption that may lead to a denial of service or, depending on the system state, arbitrary code execution.

Affected Systems

Installations of Open5GS 2.7.x and prior where the Old AMF Discovery Fallback component is enabled. The vulnerability exists in the core AMF server code and does not affect other components.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. EPSS score is not available, and the vulnerability is not listed in CISA KEV catalog, so community‑reported exploitation likelihood is uncertain. The flaw is remotely exploitable through normal service traffic, requiring network access to the AMF service and the ability to craft a specific discovery_option payload to trigger the use‑after‑free.

Generated by OpenCVE AI on September 15, 2026 at 14:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch commit ddd683a35f8aaac2b7b9884a24cd53bddfc65238 or upgrade to the latest Open5GS release that includes the fix
  • restart the AMF service after the patch to ensure no stale memory references remain
  • if the Old AMF Discovery Fallback feature is not required, disable it in the Open5GS configuration to remove the vulnerable code path

Generated by OpenCVE AI on September 15, 2026 at 14:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Open5GS up to 2.7.x. Affected is the function amf_nnrf_try_old_amf_discovery_fallback of the file src/amf/nnrf-handler.c of the component Old AMF Discovery Fallback. The manipulation of the argument discovery_option results in use after free. The attack may be performed from remote. The patch is identified as ddd683a35f8aaac2b7b9884a24cd53bddfc65238. Applying a patch is advised to resolve this issue.
Title Open5GS Old AMF Discovery Fallback nnrf-handler.c amf_nnrf_try_old_amf_discovery_fallback use after free
First Time appeared Open5gs
Open5gs open5gs
Weaknesses CWE-119
CWE-416
CPEs cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
Vendors & Products Open5gs
Open5gs open5gs
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 8.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:57:28.132Z

Reserved: 2026-09-13T08:02:06.451Z

Link: CVE-2026-90707

cve-icon Vulnrichment

Updated: 2026-09-15T13:33:50.958Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T11:17:07.103

Modified: 2026-09-15T14:17:32.230

Link: CVE-2026-90707

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:30:08Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-416

    Use After Free