CVE-2026-107166
Deferred Deferred - Pending Action

Heap Overflow in Open5GS GTP-U Receive Path

Vulnerability report for CVE-2026-107166, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: VulDB

Description

A weakness has been identified in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pfcp_xact_local_create of the file src/upf/gtp-path.c of the component GTP-U Receive Path. This manipulation causes allocation of resources. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 9ffc252482d9b03ac01abcedbe95497ff4f95dd0. It is recommended to apply a patch to fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
n/a Open5GS 2.7.0
n/a Open5GS 2.7.1
n/a Open5GS 2.7.2
n/a Open5GS 2.7.3
n/a Open5GS 2.7.4
n/a Open5GS 2.7.5
n/a Open5GS 2.7.6
n/a Open5GS 2.7.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Open5GS up to version 2.7.7, specifically in the GTP-U Receive Path component. It involves a weakness in the function ogs_pfcp_xact_local_create in the file src/upf/gtp-path.c. The issue allows remote attackers to cause resource exhaustion by sending repeated valid GTP-U Error Indication messages. This triggers the creation of unanswered PFCP Session Report Requests, leading to accumulation of local PFCP transactions and timer resources until the system crashes.

Detection Guidance

Monitor for repeated GTP-U Error Indication messages on UDP port 2152. Check for excessive PFCP Session Report Requests or local transaction accumulation in Open5GS logs. Use tools like tcpdump to capture traffic on port 2152 and analyze for abnormal patterns.

Impact Analysis

This vulnerability can cause the Open5GS UPF process to crash, disrupting network services. Attackers can remotely trigger this by sending valid but repeated Error Indication messages to UDP port 2152. The crash occurs due to resource exhaustion, specifically timer objects, leading to denial of service for the 5G core network functions.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by causing service disruptions in Open5GS, which is used in 5G core networks. A remote attacker could crash the UPF component, leading to potential data processing interruptions that may violate availability requirements in these regulations. The crash occurs due to resource exhaustion from unhandled PFCP session report requests triggered by GTP-U Error Indication messages.

Mitigation Strategies

Apply the patch from commit 9ffc252482d9b03ac01abcedbe95497ff4f95dd0. Update Open5GS to a patched version. Implement rate-limiting for Session Reports and ensure proper error handling in PFCP transaction management.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107166. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart