CVE-2026-108105: Open5GS through 2.8.0 MME Reachable Assertion via GTPv1 SGSN Context Request
Open5GS through 2.8.0 contains a reachable assertion vulnerability in mmegnhandlesgsncontextrequest() that allows remote unauthenticated attackers to crash the MME via malformed SGSN Address IEs. Attackers sending GTPv1-C traffic from a configured SGSN address with a known UE IMSI or P-TMSI can supply an invalid address length to terminate open5gs-mmed, denying service to all subscribers.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this denial-of-service condition?
Open5GS deployments through version 2.8.0 are exposed where the MME accepts GTPv1-C traffic from a configured SGSN address. Successful exploitation terminates open5gs-mmed and denies service to all subscribers served by that MME.
What does an attacker need to exploit it?
The attacker must be able to send GTPv1-C traffic from a configured SGSN address and know a UE IMSI or P-TMSI. They can then send a SGSN Context Request with a malformed SGSN Address IE containing an invalid address length.
How can I determine whether an attempted exploit has succeeded?
A successful attempt causes the open5gs-mmed process to terminate. Review MME process availability and crash or assertion logs in conjunction with malformed GTPv1 SGSN Context Request traffic.