CVE-2026-101035
Received Received - Intake

Uncaught Exception in UERANSIM nr-gnb

Vulnerability report for CVE-2026-101035, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A flaw has been found in aligungr UERANSIM up to 3.3.0. This affects the function DecodePlainMmMessage in the library src/lib/nas/encode.cpp of the component nr-gnb. Executing a manipulation can lead to uncaught exception. The attack can be launched remotely. The exploit has been published and may be used. This patch is called 1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac. It is best practice to apply a patch to resolve this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
aligungr ueransim to 3.3.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-248 An exception is thrown from a function, but it is not caught.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101035 is a flaw in aligungr UERANSIM versions up to 3.3.0 affecting the DecodePlainMmMessage function in the nr-gnb component. A remote attacker can send a manipulated message triggering an uncaught exception, causing the system to crash. The issue stems from improper handling of Initial NAS messages in the gNB component, where malformed messages lead to a denial-of-service condition.

Detection Guidance

Detect this vulnerability by monitoring for crashes in the nr-gnb component of UERANSIM. Check logs for uncaught exceptions in the DecodePlainMmMessage function. Use network traffic analysis tools like Wireshark to inspect for malformed RRC Setup Complete messages containing unknown NAS message types targeting the gNB.

Impact Analysis

This vulnerability can cause the nr-gnb component to crash, leading to a denial-of-service. If exploited, it disrupts 5G network operations managed by UERANSIM, potentially affecting testing and simulation environments. The attack can be launched remotely without authentication, making it a significant risk for systems relying on UERANSIM for 5G testing.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling denial-of-service attacks on 5G network components. A crash in the nr-gnb component due to malformed messages may disrupt network availability, which could affect data processing operations subject to these regulations. GDPR requires ensuring data availability and integrity, while HIPAA mandates reliable access to protected health information systems. The exploit may lead to unauthorized disruptions in 5G network services.

Mitigation Strategies

Apply the patch 1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac immediately. Update UERANSIM to version 3.3.1 or later. Restrict network access to the gNB component to trusted sources only. Monitor for unusual traffic patterns or crashes in the nr-gnb process.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101035. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart