CVE-2026-78157: Open5GS Rx AA-Request pcrf-rx-path.c pcrf_rx_aar_cb out-of-bounds

Published Aug 24, 2026
·
Updated

A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrfrxaarcb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Request Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. The patch is named c18dc6938bf63cc7374315d3dca303d92066e746. To fix this issue, it is recommended to deploy a patch.

Affected Software

1 affected component
open5gs open5gs=2.8.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Open5GS to a version that resolves this vulnerability.

    Patch c18dc6938bf63cc7374315d3dca303d92066e746

Event History

Aug 24, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What access does an attacker need to exploit this issue?

The issue can be initiated remotely and requires low privileges. No user interaction is required.

2

Which deployments are known to be affected?

The affected component is the Rx AA-Request Handler in Open5GS 2.8.0, specifically the pcrf_rx_aar_cb function in src/pcrf/pcrf-rx-path.c.

3

What is the impact of successful exploitation?

Successful manipulation can cause an out-of-bounds read. The supplied severity vector indicates potential low impact to confidentiality, integrity, and availability, with scope changed.

4

What should be done to remediate the issue?

Deploy the patch identified as c18dc6938bf63cc7374315d3dca303d92066e746.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203