CVE-2026-7587: Open5GS AMF nsmf-handler.c amf_nsmf_pdusession_handle_update_sm_context denial of service
A vulnerability has been found in Open5GS up to 2.7.7. This vulnerability affects the function amfnsmfpdusessionhandleupdatesmcontext of the file /src/amf/nsmf-handler.c of the component AMF. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Open5GS AMFto a version that resolves this vulnerability.Fixed in 2.7.7 - Compensating control
Apply a compensating control by limiting network access to the Open5GS AMF (e.g., restrict inbound access to the AMF interface/ports at the firewall/ACL) since the attack can be initiated remotely and causes denial of service.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7587?
CVE-2026-7587 is classified as a denial of service vulnerability affecting Open5GS up to version 2.7.7.
How do I fix CVE-2026-7587?
To fix CVE-2026-7587, upgrade to a version of Open5GS that is higher than 2.7.7.
What components are affected by CVE-2026-7587?
CVE-2026-7587 affects the AMF component, specifically the function amf_nsmf_pdusession_handle_update_sm_context in the file /src/amf/nsmf-handler.c.
What kind of attack does CVE-2026-7587 enable?
CVE-2026-7587 enables a denial of service attack, potentially causing disruptions in service for users.
Who is the vendor for CVE-2026-7587?
The vendor for CVE-2026-7587 is Open5GS.