CVE-2026-8744: Open5GS NRF context.c ogs_sbi_nf_service_add denial of service
A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function ogssbisubscriptiondataadd/ogssbinfserviceadd in the library /lib/sbi/context.c of the component NRF. Executing a manipulation can lead to denial of service. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 819db11a08b9736a3576c4f99ceb28f7eb99523a. A patch should be applied to remediate this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Open5GS NRFto a version that resolves this vulnerability.Patch 819db11a08b9736a3576c4f99ceb28f7eb99523a
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8744?
CVE-2026-8744 is classified as a denial of service vulnerability in Open5GS versions up to 2.7.7.
How do I fix CVE-2026-8744?
To fix CVE-2026-8744, update Open5GS to a version later than 2.7.7.
What component is affected by CVE-2026-8744?
CVE-2026-8744 affects the NRF component in the Open5GS library located at /lib/sbi/context.c.
What is the consequence of exploiting CVE-2026-8744?
Exploiting CVE-2026-8744 can lead to denial of service, impacting the availability of the Open5GS service.
Which versions of Open5GS are impacted by CVE-2026-8744?
Open5GS versions up to and including 2.7.7 are impacted by CVE-2026-8744.