Null Pointer Dereference in Open5GS PGW S5U Address Handler
CVE-2026-2062
Key Information:
Badges
What is CVE-2026-2062?
A vulnerability identified in the Open5GS PGW S5U Address Handler can lead to a null pointer dereference through the functions sgwc_s5c_handle_modify_bearer_response and sgwc_sxa_handle_session_modification_response. This issue can be exploited remotely, potentially allowing attackers to cause a denial of service. Publicly available exploits highlight the urgency of addressing this vulnerability. Users are strongly advised to apply the available patch (identifier: f1bbd7b57f831e2a070780a7d8d5d4c73babdb59) to safeguard their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Open5GS 2.7.0
Open5GS 2.7.1
Open5GS 2.7.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
