CVE-2026-2062: Open5GS PGW S5U Address sgwc_sxa_handle_session_modification_response null pointer dereference
A vulnerability was identified in Open5GS up to 2.7.6. This affects the function sgwcs5chandlemodifybearerresponse/sgwcsxahandlesessionmodificationresponse of the component PGW S5U Address Handler. The manipulation leads to null pointer dereference. The attack can be initiated remotely. The exploit is publicly available and might be used. The identifier of the patch is f1bbd7b57f831e2a070780a7d8d5d4c73babdb59. Applying a patch is the recommended action to fix this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2062?
The severity of CVE-2026-2062 is classified as critical due to the potential for a null pointer dereference.
How do I fix CVE-2026-2062?
To fix CVE-2026-2062, upgrade Open5GS to version 2.7.7 or later.
What components are affected by CVE-2026-2062?
CVE-2026-2062 affects the PGW S5U Address Handle component in Open5GS.
What versions of Open5GS are impacted by CVE-2026-2062?
Open5GS versions up to and including 2.7.6 are impacted by CVE-2026-2062.
What are the potential consequences of CVE-2026-2062?
The potential consequences of CVE-2026-2062 include service disruption due to application crashes.