Remote Denial of Service Vulnerability in osmo-iuh by Osmocom
CVE-2026-75894

Currently unrated

Key Information:

Vendor

Osmocom

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-75894?

In osmo-iuh versions 0.1.0 through 1.8.0, a reachable assertion exists in the ranap_handle_co_dt() function. This vulnerability allows for an arbitrarily sized NAS-PDU to trigger a process crash, resulting in a remote denial of service. Attackers exploiting this flaw could disrupt service availability, underscoring the importance of applying security patches promptly. Mitigation strategies and updates are crucial for maintaining system integrity.

Affected Version(s)

osmo-iuh 0.1.0 < 1.8.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nikolas Null "n0k0" - Security Researcher at mnemonic
.