Open5GS MME versions <= 2.6.4 contains an assertion that...
High severity
Unreviewed
Published
Jan 22, 2025
to the GitHub Advisory Database
•
Updated Jan 24, 2025
Description
Published by the National Vulnerability Database
Jan 22, 2025
Published to the GitHub Advisory Database
Jan 22, 2025
Last updated
Jan 24, 2025
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet over the S1AP interface. An attacker may repeatedly send such an oversized packet to cause the
ogs_sctp_recvmsg
routine to reach an unexpected network state and crash, leading to denial of service.References