Description
A vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function smf_n4_handle_session_report_request of the file src/smf/n4-handler.c of the component PFCP Session Report Request Handler. The manipulation leads to reachable assertion. The attack may be initiated remotely. The identifier of the patch is e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9. It is suggested to install a patch to address this issue.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (remote crash)
Action: Patch Immediately
AI Analysis

Impact

An attacker can trigger an assertion failure in the PFCP Session Report Request Handler of Open5GS, leading to an application crash and loss of availability. The flaw is caused by a manipulation of the request data that is not properly validated before the assertion is reached. Because the assertion is triggered during normal processing of a session report, a single crafted packet sent by an attacker can cause the SMF to terminate, denying service to all users currently served by that SMF instance.

Affected Systems

Open5GS implementations up to version 2.8.0 are affected. The issue resides in the function smf_n4_handle_session_report_request located in src/smf/n4-handler.c. No specific operating system or additional components are singled out; the vulnerability exists in the core Open5GS package as distributed.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact, and the EPSS score of less than 1% shows a low likelihood of exploitation in the wild. The flaw is not listed in CISA's KEV catalog. Based on the description, it is inferred that the attack vector is remote: an attacker must be able to send PFCP packets to the N4 interface of an Open5GS SMF instance. If this interface is exposed to an untrusted network, the vulnerability could be abused to crash the SMF process, potentially disrupting services for all users attached to that SMF.

Generated by OpenCVE AI on September 18, 2026 at 05:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch commit e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9 or upgrade to a fixed Open5GS release.
  • Restart the Open5GS SMF and N4 services to load the updated code.
  • Continuously monitor system logs for assertion failures or unexpected restarts to verify the fix is effective.

Generated by OpenCVE AI on September 18, 2026 at 05:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function smf_n4_handle_session_report_request of the file src/smf/n4-handler.c of the component PFCP Session Report Request Handler. The manipulation leads to reachable assertion. The attack may be initiated remotely. The identifier of the patch is e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9. It is suggested to install a patch to address this issue.
Title Open5GS PFCP Session Report Request n4-handler.c smf_n4_handle_session_report_request assertion
First Time appeared Open5gs
Open5gs open5gs
Weaknesses CWE-617
CPEs cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
Vendors & Products Open5gs
Open5gs open5gs
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-17T16:16:28.824Z

Reserved: 2026-09-16T09:37:33.269Z

Link: CVE-2026-92416

cve-icon Vulnrichment

Updated: 2026-09-17T16:16:24.459Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T18:17:21.127

Modified: 2026-09-17T17:17:49.263

Link: CVE-2026-92416

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T18:15:06Z

Weaknesses