← Terug naar overzicht

A vulnerability has been identified in Open5GS version 2.8.0 affecting the function pcrf_rx_aar_cb in the file src/pcrf/pcrf-rx-path.c within the Rx AA-Request Handler component. The vulnerability allows an out-of-bounds read condition to be triggered through manipulation of the affected function. The attack can be initiated remotely, increasing its potential impact. A patch has been developed and identified by commit hash c18dc6938bf63cc7374315d3dca303d92066e746. Affected users are strongly recommended to apply the patch immediately. The vulnerability is tracked under CVE-2026-78157 and has been referenced in both the NVD and VulDB databases. Open5GS is an open-source implementation of 5G and LTE core network components, making this vulnerability relevant to telecommunications infrastructure.

Affected products

  • Open5GS 2.8.0

Related CVE's

  • CVE-2026-78157

Categories

  • Critical Infrastructure
  • Emerging Technologies
  • Network Infrastructure