CVE-2026-8266: Open5GS SMF gsm-build.c gsm_build_pdu_session_establishment_accept denial of service
A vulnerability was detected in Open5GS up to 2.7.7. This affects the function gsmbuildpdusessionestablishmentaccept of the file /src/smf/gsm-build.c of the component SMF. The manipulation results in denial of service. The attack can be launched remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8266?
The severity of CVE-2026-8266 is categorized as a denial of service vulnerability.
How do I fix CVE-2026-8266?
To fix CVE-2026-8266, you should upgrade Open5GS SMF to version 2.7.8 or later.
What components of Open5GS are affected by CVE-2026-8266?
CVE-2026-8266 affects the Open5GS SMF component, specifically the gsm_build_pdu_session_establishment_accept function.
What versions of Open5GS are vulnerable to CVE-2026-8266?
Open5GS versions up to and including 2.7.7 are vulnerable to CVE-2026-8266.
What type of attack does CVE-2026-8266 facilitate?
CVE-2026-8266 facilitates denial of service attacks on the Open5GS SMF.