Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-108105

MEDIUM NVD
CVSS Score 5.9
Severity MEDIUM
Published Oct 09, 2026
Vendor unknown

Description

Open5GS through 2.8.0 contains a reachable assertion vulnerability in mme_gn_handle_sgsn_context_request() that allows remote unauthenticated attackers to crash the MME via malformed SGSN Address IEs. Attackers sending GTPv1-C traffic from a configured SGSN address with a known UE IMSI or P-TMSI can supply an invalid address length to terminate open5gs-mmed, denying service to all subscribers.

References