Heap-based Buffer Overflow Vulnerability in Open5GS 2.8.0
CVE-2026-78156

5.3MEDIUM

Key Information:

Vendor

Open5GS

Status
Vendor
CVE Published:
23 August 2026

What is CVE-2026-78156?

A vulnerability exists in Open5GS version 2.8.0 within the S6a Authentication-Information-Request Handler. The function hss_ogs_diam_s6a_air_cb improperly processes arguments, specifically the Visited-PLMN-Id, leading to a heap-based buffer overflow. This flaw can be exploited remotely, potentially allowing an attacker to manipulate memory and disrupt operations. It is recommended to apply the patch identified by commit a9c82ee0b590d76a581b0580cb46b598984e2392 to mitigate the risks associated with this vulnerability.

Affected Version(s)

Open5GS 2.8.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

WeiYi (VulDB User)
.