CVE-2025-44951: Buffer Overflow
A missing length check in ogspfcpdevadd function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a local attacker to cause a Buffer Overflow by changing the session.dev field with a value with length greater than 32.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44951?
CVE-2025-44951 is classified as a high severity vulnerability due to its potential to cause buffer overflows.
How do I fix CVE-2025-44951?
To mitigate CVE-2025-44951, upgrade to the latest version of Open5GS PFCP library beyond 2.7.2.
What is the impact of CVE-2025-44951?
The impact of CVE-2025-44951 allows local attackers to exploit the vulnerability by triggering a buffer overflow through manipulated input.
Which versions of Open5GS PFCP library are affected by CVE-2025-44951?
Open5GS PFCP library versions 2.7.2 and earlier are affected by CVE-2025-44951.
What components are specifically vulnerable in CVE-2025-44951?
The `ogs_pfcp_dev_add` function in the PFCP library used by both SMF and UPF components is specifically vulnerable in CVE-2025-44951.