CVE-2026-108103: Open5GS through 2.8.0 Heap Out-of-Bounds Read via PFCP Dropped DL Traffic Threshold IE
Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogspfcpparsedroppeddltrafficthreshold() that allows remote unauthenticated attackers to read past IE buffers via short IEs. Attackers can send PFCP Session Establishment or Modification Requests to the UPF on UDP port 8805 with DLPA and DLBY flags set, potentially crashing the UPF.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Open5GS deployments through version 2.8.0 are affected where an attacker can send PFCP traffic to the UPF on UDP port 8805. The vulnerable parsing path is reached by PFCP Session Establishment or Modification Requests.
What does an attacker need to send to trigger the vulnerability?
An unauthenticated remote attacker needs to send a PFCP Session Establishment or Modification Request containing a short Dropped DL Traffic Threshold IE with both the DLPA and DLBY flags set. No prior privileges or user interaction are required.
What is the practical impact?
The malformed IE causes the UPF to read past the bounds of an IE buffer. The reported consequence is a potential UPF crash, resulting in availability impact.
How can I determine whether my UPF may be affected?
Check whether the deployment uses Open5GS version 2.8.0 or earlier and whether its UPF accepts PFCP traffic on UDP port 8805 from potentially untrusted sources. Review PFCP logs or packet captures for Session Establishment or Modification Requests carrying Dropped DL Traffic Threshold IEs with DLPA and DLBY set.