An issue was discovered in Open5GS 2.7.5-49-g465e90f, when processing a PFCP Session Establishment Request (type=50), the UPF crashes with a reachable assertion in `lib/pfcp/context.c` (`ogs_pfcp_object_teid_hash_set`) if the CreatePDR?PDI?F-TEID has CH=1 and the F-TEID address-family flag(s) (IPv4/IPv6) do not match the GTP-U resource family configured for the selected DNN (Network Instance), resulting in a denial of service.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HOpen5gs
APPOpen5Gs2.7.5
Related vulnerabilities
Buffer Overflow w Open5GS v2.6.4 — podatność krytyczna w bibliotece core
Buffer Overflow w Open5GS v2.6.4 — podatność krytyczna w module PFCP
Open5GS WebUI — brak uwierzytelnienia umożliwia manipulację bazą subskrybentów
In Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in denial of servic...
Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF...