CVE-2026-75438 Details
Description
Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function
A buffer overflow vulnerability has been identified in Open5GS version 2.7.7. This vulnerability allows remote attackers to cause a denial-of-service by exploiting the ogs_sbi_time_parse() function. The issue arises when the Service Management Function (SMF) processes overly long timestamp strings in Session Management Context requests, leading to a crash of the SMF process with a stack smashing detection error.
Users are advised to update to Open5GS version 2.8.0, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/open5gs/open5gs/issues/4612 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://gist.github.com/hackeryounow/c299d593b89fd6487cab4182c8aecabf | [email protected] | Technical Description |
| https://github.com/hackeryounow/5GCVulDB/blob/main/smf_crash_uelocationtimestamp.sh | [email protected] | Broken LinkExploit |
| https://github.com/hackeryounow/5GCVulDB/tree/main/CVE-2026-75438 | [email protected] | Source Code |
| https://github.com/open5gs/open5gs/commit/7227b2f5b254160286798e058c189224360d99fc | [email protected] | Source CodeVendor |
| https://github.com/open5gs/open5gs/issues/4612 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Open5GS | v2.7.7 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion