CVE-2026-78157: Open5GS Rx AA-Request pcrf-rx-path.c pcrf_rx_aar_cb out-of-bounds
A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrfrxaarcb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Request Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. The patch is named c18dc6938bf63cc7374315d3dca303d92066e746. To fix this issue, it is recommended to deploy a patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Open5GSto a version that resolves this vulnerability.Patch c18dc6938bf63cc7374315d3dca303d92066e746
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue can be initiated remotely and requires low privileges. No user interaction is required.
Which deployments are known to be affected?
The affected component is the Rx AA-Request Handler in Open5GS 2.8.0, specifically the pcrf_rx_aar_cb function in src/pcrf/pcrf-rx-path.c.
What is the impact of successful exploitation?
Successful manipulation can cause an out-of-bounds read. The supplied severity vector indicates potential low impact to confidentiality, integrity, and availability, with scope changed.
What should be done to remediate the issue?
Deploy the patch identified as c18dc6938bf63cc7374315d3dca303d92066e746.