CVE-2026-8248: Open5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of service
A vulnerability was detected in Open5GS up to 2.7.7. The affected element is the function updateauthorizedpccruleandqos of the file /src/smf/npcf-handler.c of the component SMF. The manipulation results in denial of service. The attack may be launched remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Open5GS SMF (npcf-handler.c)to a version that resolves this vulnerability.Fixed in 2.7.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8248?
CVE-2026-8248 has been classified as a denial of service vulnerability.
How do I fix CVE-2026-8248?
To mitigate CVE-2026-8248, update Open5GS to a version newer than 2.7.7.
Which software is affected by CVE-2026-8248?
CVE-2026-8248 affects Open5GS versions up to and including 2.7.7.
What component of Open5GS is impacted by CVE-2026-8248?
The impacted component of Open5GS is the SMF, specifically the function update_authorized_pcc_rule_and_qos.
What type of attack does CVE-2026-8248 enable?
CVE-2026-8248 allows for denial of service attacks, which can disrupt the service availability.