CVE-2026-107166: Open5GS GTP-U Receive Path gtp-path.c ogs_pfcp_xact_local_create allocation of resources
A weakness has been identified in Open5GS up to 2.7.7. This vulnerability affects the function ogspfcpxactlocalcreate of the file src/upf/gtp-path.c of the component GTP-U Receive Path. This manipulation causes allocation of resources. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 9ffc252482d9b03ac01abcedbe95497ff4f95dd0. It is recommended to apply a patch to fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Open5GSto a version that resolves this vulnerability.Patch 9ffc252482d9b03ac01abcedbe95497ff4f95dd0
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Open5GS deployments up to version 2.7.7 are affected in the GTP-U receive path component. The issue can be exploited remotely.
Does exploiting this issue require authentication or user interaction?
No. The provided vector indicates network access with low attack complexity, no privileges required, and no user interaction.
What is the likely impact of successful exploitation?
The weakness causes resource allocation and is rated as having low availability impact. The provided information does not identify confidentiality or integrity impact.
What should teams do to remediate it?
Apply patch 9ffc252482d9b03ac01abcedbe95497ff4f95dd0. Public exploit availability is reported, so remediation should be prioritized.