Out of Bounds Write Vulnerability in osmo-ggsn by Osmocom
CVE-2026-75892

Currently unrated

Key Information:

Vendor

Osmocom

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-75892?

An out of bounds write vulnerability has been identified in osmo-ggsn version 1.14.0. This issue arises in the gtp_decode_pdp_ctx() function, specifically when processing the PDP context GSN-Address sub-field. Exploitation of this vulnerability can lead to memory corruption, which may allow an attacker to manipulate memory segments and potentially execute arbitrary code. Users are advised to review the available patches and mitigate the risks associated with this vulnerability to safeguard their systems.

Affected Version(s)

osmo-ggsn 1.14.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nikolas Null "n0k0" - Security Researcher at mnemonic
.