CVE-2026-8224: Open5GS PCF context.c pcf_sess_set_ipv6prefix denial of service
A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function pcfsesssetipv6prefix of the file /src/pcf/context.c of the component PCF. Executing a manipulation of the argument SmPolicyContextData.ipv6AddressPrefix can lead to denial of service. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8224?
CVE-2026-8224 is classified as a denial of service vulnerability affecting Open5GS PCF versions up to 2.7.7.
How do I fix CVE-2026-8224?
To fix CVE-2026-8224, upgrade Open5GS PCF to version 2.7.8 or later.
What component is affected by CVE-2026-8224?
CVE-2026-8224 affects the PCF component of Open5GS, specifically the function pcf_sess_set_ipv6prefix.
What versions of Open5GS are impacted by CVE-2026-8224?
Open5GS versions up to and including 2.7.7 are impacted by CVE-2026-8224.
What kind of issue does CVE-2026-8224 cause?
CVE-2026-8224 causes a denial of service issue when certain arguments are manipulated in the PCF.