CVE-2026-30077 Details
Description
OpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But the crash is consistent for particular inputs. An example input in hex stream is 80 00 00 0E 00 00 01 00 0F 80 02 02 40 00 58 00 01 88.
A denial-of-service vulnerability has been identified in OpenAirInterface AMF version 2.2.0. The issue arises when the AMF fails to decode certain NGAP messages, leading to a crash. While not all decoding errors cause a crash, specific inputs consistently trigger this failure. The vulnerability was discovered in a Docker deployment on Ubuntu 22.04 Server.
Users can update to OpenAirInterface AMF version 2.2.1, which includes a fix for this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/issues/76 | [email protected] | Issue TrackingThird Party Advisory |
| https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/merge_requests/414 | [email protected] | Issue TrackingMitigation |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| openairinterface openairinterface | 2.2.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 6, 2026 | Initial Analysis | [email protected] |
| Mar 30, 2026 | CVE Modified | CISA-ADP |
| Mar 30, 2026 | New CVE Received | [email protected] |