Remote Code Execution Flaw in aligungr UERANSIM Radio Link Simulation Layer
CVE-2026-7183

6.9MEDIUM

Key Information:

Vendor

Aligungr

Status
Vendor
CVE Published:
27 April 2026

What is CVE-2026-7183?

A vulnerability has been discovered in aligungr UERANSIM up to version 3.2.7, specifically within the rls::DecodeRlsMessage function in the Radio Link Simulation Layer. This issue arises from improper handling of the pduLength argument, which can result in an uncaught exception. Attackers can exploit this vulnerability remotely, potentially leading to system disruption or instability. It is strongly recommended that users upgrade to version 3.2.8 or later to mitigate this risk. The vendor has effectively addressed the issue, demonstrating a proactive approach in releasing a timely fix.

Affected Version(s)

UERANSIM 3.2.0

UERANSIM 3.2.1

UERANSIM 3.2.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0wln3d (VulDB User)
VulDB CNA Team
.