Out-of-Bounds Write Vulnerability in Open5GS Shared NF-profile Parser
CVE-2026-10114
Key Information:
Badges
What is CVE-2026-10114?
A critical vulnerability exists in Open5GS versions up to 2.7.7, specifically in the function handle_scp_info within the shared NF-profile parser component. This vulnerability allows remote attackers to exploit the system through an out-of-bounds write, potentially leading to data corruption or service disruption. It is essential for users to implement the provided patch to mitigate this issue and protect their systems from possible exploitation.
Affected Version(s)
Open5GS 2.7.0
Open5GS 2.7.1
Open5GS 2.7.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
