CVE-2026-82588
Received Received - Intake

Null Pointer Dereference in Open5GS

Vulnerability report for CVE-2026-82588, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-30

Last updated on: 2026-08-30

Assigner: VulDB

Description

A vulnerability was identified in Open5GS up to 2.7.7. This issue affects some unknown processing of the file src/amf/namf-handler.c of the component Transfer Endpoint. Such manipulation leads to null pointer dereference. The attack can be launched remotely. Upgrading to version 2.8.0 is capable of addressing this issue. The name of the patch is abf8a836564b966b5141110fc25ed413c4f17522. Upgrading the affected component is advised.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-30
Last Modified
2026-08-30
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open5gs open5gs to 2.7.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a null pointer dereference issue in Open5GS versions up to 2.7.7. It occurs in the file src/amf/namf-handler.c during processing of the Transfer Endpoint component. A remote attacker can exploit this to cause a denial of service by crashing the application.

Detection Guidance

This vulnerability is specific to Open5GS versions up to 2.7.7 and involves a null pointer dereference in the AMF component. Detection would require checking the installed version of Open5GS on your system. Run: open5gs --version or check package managers like apt or yum for the installed version.

Impact Analysis

The vulnerability allows remote attackers to crash the Open5GS application, leading to service disruption. If Open5GS is part of a critical network infrastructure, this could cause downtime or loss of connectivity for users relying on the service.

Compliance Impact

This vulnerability, a null pointer dereference in Open5GS, could potentially lead to denial of service or unauthorized access if exploited. While not directly tied to GDPR or HIPAA, such disruptions may impact data availability and integrity, which are key compliance requirements under these regulations.

Mitigation Strategies

Upgrade Open5GS to version 2.8.0 or later to address the vulnerability. The patch is identified as abf8a836564b966b5141110fc25ed413c4f17522. Follow standard upgrade procedures for your system or containerized deployment.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82588. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart