CVE-2025-15532 Details
Description
A security flaw has been discovered in Open5GS up to 2.7.5. This issue affects some unknown processing of the component Timer Handler. The manipulation results in resource consumption. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The patch is identified as c7c131f8d2cb1195ada5e0e691b6868ebcd8a845. It is best practice to apply a patch to resolve this issue.
A denial-of-service vulnerability has been identified in Open5GS versions through 2.7.5. The issue arises in the SGW-C component, specifically within the Timer Handler, where improper management of timer resources allows for excessive consumption. This vulnerability can be exploited remotely, without authentication, by sending a high volume of GTPv2 Create Session Request messages. As the SGW-C UE and session context pools become saturated, the application fails to allocate necessary timer resources, triggering fatal assertions that cause the service to crash and dump core. This behavior disrupts normal operations and service continuity.
Users are advised to update to Open5GS version 2.7.6 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/open5gs/open5gs/ | [email protected] | |
| https://github.com/open5gs/open5gs/commit/c7c131f8d2cb1195ada5e0e691b6868ebcd8a845 | [email protected] | Patch |
| https://github.com/open5gs/open5gs/issues/4220 | [email protected] | ExploitIssue TrackingVendor Advisory |
| https://github.com/open5gs/open5gs/issues/4220#issue-3766066853 | [email protected] | ExploitIssue TrackingVendor Advisory |
| https://github.com/open5gs/open5gs/issues/4221 | [email protected] | ExploitIssue TrackingVendor Advisory |
| https://vuldb.com/?ctiid.341599 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.341599 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.729354 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.729357 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.735340 | [email protected] | |
| https://vuldb.com/?submit.735341 | [email protected] | |
| https://vuldb.com/?submit.735342 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| open5gs open5gs | <= 2.7.5 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 23, 2026 | CVE Modified | [email protected] |
| Feb 9, 2026 | Initial Analysis | [email protected] |
| Jan 17, 2026 | New CVE Received | [email protected] |