CVE-2026-108102
Deferred Deferred - Pending Action

Heap Out-of-Bounds Read in Open5GS

Vulnerability report for CVE-2026-108102, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: VulnCheck

Description

Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_volume_measurement() in lib/pfcp/types.c that allows remote unauthenticated attackers to read past IE buffers. Attackers can send a PFCP Session Report Request to the SMF on UDP port 8805 with a short, all-flags Volume Measurement IE, reading up to 48 bytes and potentially crashing the SMF.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open5gs open5gs 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Open5GS through version 2.8.0 has a heap out-of-bounds read flaw in the function ogs_pfcp_parse_volume_measurement() located in lib/pfcp/types.c. This issue allows remote unauthenticated attackers to read memory beyond the intended IE buffers by sending a specially crafted PFCP Session Report Request to the SMF on UDP port 8805. The attacker can include a short Volume Measurement IE with all flags set, which may result in reading up to 48 bytes of adjacent memory and potentially crashing the SMF service.

Detection Guidance

Detecting this vulnerability requires monitoring for PFCP Session Report Requests with malformed Volume Measurement IEs on UDP port 8805. Inspect network traffic for unexpected payloads or crashes in the SMF service. Check logs for heap out-of-bounds read errors in Open5GS versions before 2.8.1.

Impact Analysis

This vulnerability can lead to denial of service by crashing the SMF component of Open5GS, disrupting network services. It may also expose sensitive memory contents, potentially leaking information. Attackers could exploit this to gather data or destabilize the network without authentication.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by exposing sensitive data through heap out-of-bounds reads. Unauthorized memory access may lead to leakage of personal or health information if exploited, violating data protection requirements under these regulations.

Mitigation Strategies

Upgrade Open5GS to version 2.8.1 or later to patch the vulnerability. Block or filter PFCP traffic on UDP port 8805 if not required. Monitor SMF service stability and apply network segmentation to limit exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108102. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart