Description
A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the library lib/pfcp/types.c of the component PFCP Handler. The manipulation results in null pointer dereference. The attack may be launched remotely. The patch is identified as 8f07b507b78ff94776f2cd49276eb116ed93d7f2. A patch should be applied to remediate this issue.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Remote Null Pointer Dereference
Action: Immediate Patch
AI Analysis

Impact

A null pointer dereference occurs in the ogs_pfcp_parse_volume_measurement function within the PFCP Handler of Open5GS. When malformed PFCP messages are processed, the code attempts to dereference a null pointer, causing the PFCP service to crash or become unresponsive. The resulting denial of service can disrupt mobile network control plane operations. This weakness is consistent with CWE-476 and CWE-404, indicating uninitialized or null pointer dereferencing.

Affected Systems

Open5GS, the open-source 5G core network stack, is affected through all releases up to and including version 2.8.0. Operators running these firmware layers are at risk if they have not applied the upstream patch that fixes the issue.

Risk and Exploitability

The CVSS score of 7.1 reflects a moderate to high impact when exploited. With an EPSS score of less than 1 %, the likelihood of a widespread, automated exploitation campaign is currently low. However, because the attack can be launched remotely and does not require privileged access, it remains a viable target for adversaries with network reach to the PFCP endpoint. The vulnerability is not listed in the CISA KEV catalog as of this analysis, so no known active exploits have been reported, but the patch is strongly recommended.

Generated by OpenCVE AI on September 18, 2026 at 05:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Open5GS patch identified by commit 8f07b507b78ff94776f2cd49276eb116ed93d7f2 to correct the null pointer dereference.
  • Upgrade Open5GS to version 2.8.1 or later, which incorporates the patch and any related stability improvements.
  • Restart the PFCP service or the entire Open5GS deployment to ensure the updated code is loaded and operational.
  • Limit PFCP traffic to trusted networks or enforce strict authentication to reduce exposure until the patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 05:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the library lib/pfcp/types.c of the component PFCP Handler. The manipulation results in null pointer dereference. The attack may be launched remotely. The patch is identified as 8f07b507b78ff94776f2cd49276eb116ed93d7f2. A patch should be applied to remediate this issue.
Title Open5GS PFCP types.c ogs_pfcp_parse_volume_measurement null pointer dereference
First Time appeared Open5gs
Open5gs open5gs
Weaknesses CWE-404
CWE-476
CPEs cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
Vendors & Products Open5gs
Open5gs open5gs
References
Metrics cvssV2_0

{'score': 6.8, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:C/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T15:45:20.943Z

Reserved: 2026-09-16T09:37:36.932Z

Link: CVE-2026-92417

cve-icon Vulnrichment

Updated: 2026-09-22T15:05:50.973Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T19:18:05.933

Modified: 2026-09-22T16:18:11.857

Link: CVE-2026-92417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:45:04Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-476

    NULL Pointer Dereference