Back to CVE List

CVE-2026-30075

HIGH SEVERITY

CVSS Score & Metrics

Base Score
7.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Description

OpenAirInterface Version 2.2.0 has a Buffer Overflow vulnerability in processing UplinkNASTransport containing Authentication Response containing a NAS PDU with oversize response (For example 100 byte). The response is decoded by AMF and passed to the AUSF component for verification. AUSF crashes on receiving this oversize response. This can prohibit users from further registration and verification and can cause Denial of Services (DoS).

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-120
Source
NVD
Vendor
openairinterface
Product
oai-cn5g-amf

External References

Discussion (0)

Add Comment

No comments yet. Be the first!