CVE-2026-8288: Open5GS SMF gsm-handler.c denial of service
A vulnerability was determined in Open5GS up to 2.7.7. This affects the function gsmhandlepdusessionmodificationqosflowdescriptions of the file src/smf/gsm-handler.c of the component SMF. Executing a manipulation of the argument n1SmMsg can lead to denial of service. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8288?
CVE-2026-8288 has been categorized as a denial of service vulnerability.
How do I fix CVE-2026-8288?
To fix CVE-2026-8288, upgrade Open5GS SMF to version 2.7.8 or later.
What software versions are affected by CVE-2026-8288?
CVE-2026-8288 affects Open5GS SMF versions up to and including 2.7.7.
What component is impacted by CVE-2026-8288?
The CVE-2026-8288 vulnerability impacts the SMF component of Open5GS.
How can CVE-2026-8288 be exploited?
CVE-2026-8288 can be exploited by manipulating the argument n1SmMsg in the gsm_handle_pdu_session_modification_qos_flow_descriptions function.