CVE-2025-15176: Open5GS PFCP Session Establishment Request rule-match.c ogs_pfcp_pdr_rule_find_by_packet assertion
A flaw has been found in Open5GS up to 2.7.5. This affects the function decodeipv6header/ogspfcppdrrulefindbypacket of the file lib/pfcp/rule-match.c of the component PFCP Session Establishment Request Handler. Executing a manipulation can lead to reachable assertion. It is possible to launch the attack remotely. The exploit has been published and may be used. This patch is called b72d8349980076e2c033c8324f07747a86eea4f8. Applying a patch is advised to resolve this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15176?
CVE-2025-15176 is classified as a high severity vulnerability due to the potential for assertion failures leading to denial of service.
How do I fix CVE-2025-15176?
To fix CVE-2025-15176, upgrade Open5GS to version 2.7.6 or later, as this version addresses the identified flaw.
Which versions of Open5GS are affected by CVE-2025-15176?
Open5GS versions up to and including 2.7.5 are affected by CVE-2025-15176.
What component of Open5GS is impacted by CVE-2025-15176?
CVE-2025-15176 impacts the PFCP Session Establishment Request Handler in the file lib/pfcp/rule-match.c.
Is there a known exploit for CVE-2025-15176?
Yes, there are indications that manipulation can lead to reachable assertion failures, suggesting the potential for exploitation.