CVE-2026-4240: Open5GS CCA smf_s6b_sta_cb denial of service
A vulnerability was determined in Open5GS up to 2.7.6. The affected element is the function smfgxccacb/smfgyccacb/smfs6baaacb/smfs6bstacb of the component CCA Handler. This manipulation causes denial of service. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.7.7 is sufficient to fix this issue. Patch name: 80eb484a6ab32968e755e628b70d1a9c64f012ec. Upgrading the affected component is recommended.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4240?
CVE-2026-4240 is classified as a denial of service vulnerability in Open5GS up to version 2.7.6.
How can I mitigate CVE-2026-4240?
To mitigate CVE-2026-4240, upgrade Open5GS to a version beyond 2.7.6 where the vulnerability is patched.
What versions of Open5GS are affected by CVE-2026-4240?
Open5GS versions up to and including 2.7.6 are vulnerable to CVE-2026-4240.
What components are impacted by CVE-2026-4240?
CVE-2026-4240 affects the CCA Handler component, specifically the smf_s6b_sta_cb function.
Can CVE-2026-4240 be exploited remotely?
Yes, CVE-2026-4240 can be exploited remotely to cause denial of service.