Heap-based Buffer Overflow in Open5GS S6a Authentication-Information-Request Handler
Open5GS 2.8.0 contains a remote heap-based buffer overflow vulnerability (CVE-2026-78156) in the S6a Authentication-Information-Request Handler that can be triggered by manipulating the Visited-PLMN-Id argument.
CVE search metadata
CVE search record: CVE-2026-78156. Severity: high. CVSS: 7.4. KEV: no. Product: Open5GS (2.8.0). Brief: Heap-based Buffer Overflow in Open5GS S6a Authentication-Information-Request Handler. Brief link: https://feed.craftedsignal.io/briefs/2026-08-open5gs-overflow/
A heap-based buffer overflow vulnerability has been identified in Open5GS version 2.8.0, specifically impacting the S6a Authentication-Information-Request Handler. The flaw exists within the hss_ogs_diam_s6a_air_cb function located in the file src/hss/hss-s6a-path.c. An attacker can remotely exploit this vulnerability by providing a specially crafted Visited-PLMN-Id argument to the HSS component. Successful exploitation could lead to memory corruption, potentially causing service crashes or arbitrary code execution. The vulnerability is addressed in the commit a9c82ee0b590d76a581b0580cb46b598984e2392. This issue is significant for operators of 5G core networks using the Open5GS framework, as it allows for unauthorized interaction with the S6a interface.
Attack Chain
- Attacker establishes network connectivity to the Diameter S6a interface exposed by the Open5GS HSS component.
- Attacker initiates an Authentication-Information-Request (AIR) Diameter message.
- Attacker crafts the
Visited-PLMN-Idparameter in the DIAMETER message with excessive or malformed data designed to exceed allocated buffer boundaries. - The HSS component parses the incoming message using the vulnerable
hss_ogs_diam_s6a_air_cbfunction. - The function copies the malicious
Visited-PLMN-Idvalue into a heap-allocated buffer without adequate bounds checking. - Memory corruption occurs due to the heap-based buffer overflow, overwriting adjacent heap structures.
- Attacker triggers a crash or redirects execution flow to achieve unauthorized impact.
Impact
The vulnerability poses a high risk to the confidentiality, integrity, and availability of 5G core network infrastructure utilizing Open5GS 2.8.0. Successful exploitation of this remote buffer overflow can lead to denial-of-service via service disruption or potential remote code execution on the server hosting the HSS process, compromising core authentication services.
Recommendation
- Immediately update Open5GS deployments to a version containing the fix for commit
a9c82ee0b590d76a581b0580cb46b598984e2392. - Implement network-level access control lists (ACLs) to restrict access to the Diameter S6a interface to authorized network elements only.
- Monitor logs for unusual Diameter traffic patterns or unexpected crashes of the HSS process.
- Review network configurations to ensure that the HSS component is not unnecessarily exposed to untrusted external networks.
Immediate actions
Patch Open5GS to current release
Mitigations
Restrict S6a network access
CVE-2026-78156