CVE-2026-100892
Received Received - Intake

Memory Corruption in UERANSIM nr-gnb

Vulnerability report for CVE-2026-100892, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was found in aligungr UERANSIM up to 3.3.0. This affects the function ULInformationTransfer of the file src/gnb/rrc/handler.cpp of the component nr-gnb. Performing a manipulation of the argument dedicatedNASMessage results in memory corruption. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
aligungr ueransim to 3.3.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-119 The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-100892 is a memory corruption vulnerability in UERANSIM's nr-gnb component affecting versions up to 3.3.0. It occurs when the dedicatedNASMessage argument in the ULInformationTransfer function is manipulated, leading to memory corruption. The attack can be executed remotely by sending a malformed ULInformationTransfer message.

Detection Guidance

Monitor for crashes in the UERANSIM nr-gnb component, particularly segmentation faults (SIGSEGV). Check logs for malformed ULInformationTransfer messages or NULL pointer dereferences in the dedicatedNASMessage field. Use network traffic analysis tools like Wireshark to inspect RLS messages sent to port 4997 for unusual sequences.

Impact Analysis

This vulnerability can cause a Denial-of-Service (DoS) condition by crashing the gNB component of UERANSIM. An attacker could remotely exploit it by sending a sequence of RLS messages, including a heartbeat and the malformed message, resulting in the target system becoming unavailable.

Compliance Impact

This vulnerability primarily causes a Denial-of-Service (DoS) condition by crashing the gNB component, which could disrupt network availability. While it does not directly expose or leak data, prolonged or repeated outages may impact compliance with regulations like GDPR (availability requirements) or HIPAA (service continuity for healthcare systems). However, the provided context does not specify direct compliance impacts.

Mitigation Strategies

Update UERANSIM to a patched version if available. If not, restrict network access to port 4997 using firewalls. Implement input validation for ULInformationTransfer messages to prevent NULL pointer dereferences. Monitor for suspicious RLS message sequences targeting the gNB.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100892. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart