CVE-2026-30078 Details
Description
OpenAirInterface V2.2.0 AMF crashes when it receives an NGAP message with invalid procedure code or invalid PDU-type. For example when the message specification requires InitiatingMessage but sent with successfulOutcome.
A vulnerability in OpenAirInterface AMF version 2.2.0 leads to a crash when the application receives an NGAP message with an invalid procedure code or PDU type. For instance, a message that requires an 'InitiatingMessage' but is sent as a 'successfulOutcome' will trigger this issue. The crash occurs because the application attempts to free a memory address that was not allocated, indicating a memory management error.
Users can update to OpenAirInterface AMF version 2.2.1, which includes a fix for this vulnerability by updating the NGAP procedure code handling to align with the latest 3GPP specifications.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/issues/74 | [email protected] | ExploitIssue Tracking |
| https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/merge_requests/414 | [email protected] | Issue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| openairinterface oai-cn5g-amf | 2.2.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 10, 2026 | Initial Analysis | [email protected] |
| Apr 6, 2026 | CVE Modified | CISA-ADP |
| Apr 6, 2026 | New CVE Received | [email protected] |