CVE-2026-108103: Open5GS through 2.8.0 Heap Out-of-Bounds Read via PFCP Dropped DL Traffic Threshold IE

Published Oct 9, 2026
·
Updated

Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogspfcpparsedroppeddltrafficthreshold() that allows remote unauthenticated attackers to read past IE buffers via short IEs. Attackers can send PFCP Session Establishment or Modification Requests to the UPF on UDP port 8805 with DLPA and DLBY flags set, potentially crashing the UPF.

Affected Software

1 affected component
open5gs open5gs<=2.8.0

Event History

Oct 9, 2026
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Open5GS deployments through version 2.8.0 are affected where an attacker can send PFCP traffic to the UPF on UDP port 8805. The vulnerable parsing path is reached by PFCP Session Establishment or Modification Requests.

2

What does an attacker need to send to trigger the vulnerability?

An unauthenticated remote attacker needs to send a PFCP Session Establishment or Modification Request containing a short Dropped DL Traffic Threshold IE with both the DLPA and DLBY flags set. No prior privileges or user interaction are required.

3

What is the practical impact?

The malformed IE causes the UPF to read past the bounds of an IE buffer. The reported consequence is a potential UPF crash, resulting in availability impact.

4

How can I determine whether my UPF may be affected?

Check whether the deployment uses Open5GS version 2.8.0 or earlier and whether its UPF accepts PFCP traffic on UDP port 8805 from potentially untrusted sources. Review PFCP logs or packet captures for Session Establishment or Modification Requests carrying Dropped DL Traffic Threshold IEs with DLPA and DLBY set.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203