Null Pointer Dereference in Open5GS PFCP Handler
CVE-2026-92417

7.1HIGH

Key Information:

Vendor

Open5GS

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92417?

A null pointer dereference vulnerability exists in Open5GS versions up to 2.8.0, specifically within the PFCP Handler's function ogs_pfcp_parse_volume_measurement in the lib/pfcp/types.c library. This issue allows for potential remote attacks that can cause denial of service due to improper handling of volume measurement data. Users are advised to apply the patch identified with commit hash 8f07b507b78ff94776f2cd49276eb116ed93d7f2 promptly to mitigate the risks associated with this vulnerability.

Affected Version(s)

Open5GS 2.0

Open5GS 2.1

Open5GS 2.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

WeiYi (VulDB User)
.