CVE-2026-82590: Open5GS SMF nudm-handler.c smf_nudm_sdm_handle_get assertion
A weakness has been identified in Open5GS up to 2.7.7. The affected element is the function smfnudmsdmhandleget of the file src/smf/nudm-handler.c of the component SMF. Executing a manipulation of the argument preemptCap can lead to reachable assertion. The attack may be launched remotely. Upgrading to version 2.8.0 is sufficient to fix this issue. This patch is called 4554405f29bffd7562abedbee63484825bd90cd5. You should upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Open5GS SMFto a version that resolves this vulnerability.Fixed in 2.8.0Patch 4554405f29bffd7562abedbee63484825bd90cd5
Event History
Frequently Asked Questions
Which deployments are affected?
Open5GS SMF deployments using versions up to 2.7.7 are affected. The issue is in the SMF component's handling of the preemptCap argument.
What does an attacker need to exploit this issue?
The attack can be launched remotely and requires manipulation of the preemptCap argument. The supplied severity vector indicates low privileges are required and no user interaction is needed.
What is the likely impact of successful exploitation?
Manipulating preemptCap can reach an assertion in smf_nudm_sdm_handle_get, resulting in an availability impact. The provided vector indicates no confidentiality or integrity impact.
How should this be remediated?
Upgrade the affected Open5GS SMF component to version 2.8.0. The fixing patch is 4554405f29bffd7562abedbee63484825bd90cd5.