Use After Free Vulnerability in Open5GS by Open5GS
CVE-2026-90707
6.9MEDIUM
What is CVE-2026-90707?
A security flaw has been identified in Open5GS, affecting versions up to 2.7.x. The vulnerability resides in the function amf_nnrf_try_old_amf_discovery_fallback located in src/amf/nnrf-handler.c. An improper handling of the discovery_option argument may lead to a use after free condition, which can be exploited remotely. Users are advised to apply the patch identified by commit ddd683a35f8aaac2b7b9884a24cd53bddfc65238 to mitigate this issue.
Affected Version(s)
Open5GS 2.0
Open5GS 2.1
Open5GS 2.2
