Heap Out-of-Bounds Read Vulnerability in Open5GS by Open5GS
CVE-2026-108103
6.9MEDIUM
What is CVE-2026-108103?
Open5GS versions prior to 2.8.0 are susceptible to a heap out-of-bounds read vulnerability in the function ogs_pfcp_parse_dropped_dl_traffic_threshold(). This flaw enables remote unauthenticated attackers to read beyond the intended boundary of information elements (IEs) by sending specially crafted PFCP Session Establishment or Modification Requests to the User Plane Function (UPF) over UDP port 8805, with the DLPA and DLBY flags set. Exploitation of this vulnerability could lead to unintended behavior or crashes in the UPF, posing significant security risks.
Affected Version(s)
open5gs 0 <= 2.8.0
