7.4highHigh
CVE-2026-78157
A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Request Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. The patch is named c18dc6938bf63cc7374315d3dca303d92066e746. To fix this issue, it is recommended to deploy a patch.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, an ordinary user account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 7.4 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L- CVSS v4
- 2.1
- Weakness
- CWE-119
- Assigned by
- cna@vuldb.com
Dates
- Published
- 2026-08-24
- Last modified
- 2026-08-24
- Sources
- NVD
References
- https://github.com/open5gs/open5gs/
- https://github.com/open5gs/open5gs/commit/c18dc6938bf63cc7374315d3dca303d92066e746
- https://github.com/open5gs/open5gs/issues/4663
- https://vuldb.com/cve/CVE-2026-78157
- https://vuldb.com/submit/882953
- https://vuldb.com/vuln/394540
- https://vuldb.com/vuln/394540/cti
- https://github.com/open5gs/open5gs/issues/4663