CVE-2026-101035 Details
Description
A flaw has been found in aligungr UERANSIM up to 3.3.0. This affects the function DecodePlainMmMessage in the library src/lib/nas/encode.cpp of the component nr-gnb. Executing a manipulation can lead to uncaught exception. The attack can be launched remotely. The exploit has been published and may be used. This patch is called 1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac. It is best practice to apply a patch to resolve this issue.
A vulnerability allowing for a denial-of-service condition has been identified in aligungr UERANSIM versions through 3.3.0. The issue arises in the nr-gnb component, specifically within the DecodePlainMmMessage function of the encoding library. The vulnerability can be exploited remotely by sending a series of manipulated RLS messages, including a malformed RRC Setup Complete message that carries an unknown NAS message type. This manipulation leads to an uncaught exception, causing the gNodeB simulation to crash.
Users are advised to update to the patched version of UERANSIM, which is available on the UERANSIM GitHub Releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/centauruszzz/f729edf89aa32ae3cfe4865c71ad1102 | [email protected] | ExploitTechnical Description |
| https://github.com/aligungr/UERANSIM/ | [email protected] | ProductVendor |
| https://github.com/aligungr/UERANSIM/commit/1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac | [email protected] | Source CodeVendor |
| https://vuldb.com/cve/CVE-2026-101035 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/926089 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/410903 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/410903/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-248 | Uncaught Exception | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| aligungr UERANSIM | <= 3.3.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion