CVE-2026-100892: aligungr UERANSIM nr-gnb handler.cpp ULInformationTransfer memory corruption
A vulnerability was found in aligungr UERANSIM up to 3.3.0. This affects the function ULInformationTransfer of the file src/gnb/rrc/handler.cpp of the component nr-gnb. Performing a manipulation of the argument dedicatedNASMessage results in memory corruption. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be considered affected?
Deployments using the nr-gnb component in aligungr UERANSIM versions up to and including 3.3.0 should be considered affected. The vulnerable code is in src/gnb/rrc/handler.cpp.
Does an attacker need credentials or user interaction to exploit this issue?
The issue can be initiated remotely. The supplied vector indicates no privileges and no user interaction are required.
What is known about exploit availability and remediation?
A public exploit has been disclosed and could be used. The vendor was contacted but did not respond, and the available data does not identify a fixed version or workaround.