CVE-2025-8698: Open5GS AMF Service nsmf-handler.c amf_nsmf_pdusession_handle_release_sm_context assertion
A vulnerability was found in Open5GS up to 2.7.5. It has been classified as problematic. Affected is the function amfnsmfpdusessionhandlereleasesmcontext of the file src/amf/nsmf-handler.c of the component AMF Service. The manipulation leads to reachable assertion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The name of the patch is 66bc558e417e70ae216ec155e4e81c14ae0ecf30. It is recommended to apply a patch to fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Open5GS AMF Serviceto a version that resolves this vulnerability.Fixed in 2.7.5Patch 66bc558e417e70ae216ec155e4e81c14ae0ecf30
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8698?
CVE-2025-8698 has been classified as problematic due to its potential impact on the AMF Service in Open5GS.
How do I fix CVE-2025-8698?
To fix CVE-2025-8698, update your Open5GS installation to a version later than 2.7.5.
What components are affected by CVE-2025-8698?
CVE-2025-8698 affects the AMF Service specifically in the function amf_nsmf_pdusession_handle_release_sm_context.
What type of vulnerability is CVE-2025-8698?
CVE-2025-8698 is classified as a reachability vulnerability resulting in an assertion failure.
Which versions of Open5GS are impacted by CVE-2025-8698?
Open5GS versions up to and including 2.7.5 are impacted by CVE-2025-8698.