CVE-2026-90707: Open5GS Old AMF Discovery Fallback nnrf-handler.c amf_nnrf_try_old_amf_discovery_fallback use after free
A security flaw has been discovered in Open5GS up to 2.7.x. Affected is the function amfnnrftryoldamfdiscoveryfallback of the file src/amf/nnrf-handler.c of the component Old AMF Discovery Fallback. The manipulation of the argument discoveryoption results in use after free. The attack may be performed from remote. The patch is identified as ddd683a35f8aaac2b7b9884a24cd53bddfc65238. Applying a patch is advised to resolve this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Open5GS (Old AMF Discovery Fallback: src/amf/nnrf-handler.c, amf_nnrf_try_old_amf_discovery_fallback)to a version that resolves this vulnerability.Patch ddd683a35f8aaac2b7b9884a24cd53bddfc65238
Event History
Frequently Asked Questions
Which deployments are affected?
Open5GS deployments using versions up to 2.7.x are affected in the Old AMF Discovery Fallback component, specifically the amf_nnrf_try_old_amf_discovery_fallback function in src/amf/nnrf-handler.c.
Does exploitation require local access, credentials, or user interaction?
No. The supplied vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What is the recommended remediation?
Apply patch ddd683a35f8aaac2b7b9884a24cd53bddfc65238. The provided information does not identify an alternative mitigation for environments that cannot immediately apply the patch.