{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/open5gs/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-78156"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Open5GS (2.8.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Open5GS"],"content_html":"\u003cp\u003eA heap-based buffer overflow vulnerability has been identified in Open5GS version 2.8.0, specifically impacting the S6a Authentication-Information-Request Handler. The flaw exists within the \u003ccode\u003ehss_ogs_diam_s6a_air_cb\u003c/code\u003e function located in the file \u003ccode\u003esrc/hss/hss-s6a-path.c\u003c/code\u003e. An attacker can remotely exploit this vulnerability by providing a specially crafted \u003ccode\u003eVisited-PLMN-Id\u003c/code\u003e argument to the HSS component. Successful exploitation could lead to memory corruption, potentially causing service crashes or arbitrary code execution. The vulnerability is addressed in the commit \u003ccode\u003ea9c82ee0b590d76a581b0580cb46b598984e2392\u003c/code\u003e. This issue is significant for operators of 5G core networks using the Open5GS framework, as it allows for unauthorized interaction with the S6a interface.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes network connectivity to the Diameter S6a interface exposed by the Open5GS HSS component.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an Authentication-Information-Request (AIR) Diameter message.\u003c/li\u003e\n\u003cli\u003eAttacker crafts the \u003ccode\u003eVisited-PLMN-Id\u003c/code\u003e parameter in the DIAMETER message with excessive or malformed data designed to exceed allocated buffer boundaries.\u003c/li\u003e\n\u003cli\u003eThe HSS component parses the incoming message using the vulnerable \u003ccode\u003ehss_ogs_diam_s6a_air_cb\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eThe function copies the malicious \u003ccode\u003eVisited-PLMN-Id\u003c/code\u003e value into a heap-allocated buffer without adequate bounds checking.\u003c/li\u003e\n\u003cli\u003eMemory corruption occurs due to the heap-based buffer overflow, overwriting adjacent heap structures.\u003c/li\u003e\n\u003cli\u003eAttacker triggers a crash or redirects execution flow to achieve unauthorized impact.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a high risk to the confidentiality, integrity, and availability of 5G core network infrastructure utilizing Open5GS 2.8.0. Successful exploitation of this remote buffer overflow can lead to denial-of-service via service disruption or potential remote code execution on the server hosting the HSS process, compromising core authentication services.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update Open5GS deployments to a version containing the fix for commit \u003ccode\u003ea9c82ee0b590d76a581b0580cb46b598984e2392\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eImplement network-level access control lists (ACLs) to restrict access to the Diameter S6a interface to authorized network elements only.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual Diameter traffic patterns or unexpected crashes of the HSS process.\u003c/li\u003e\n\u003cli\u003eReview network configurations to ensure that the HSS component is not unnecessarily exposed to untrusted external networks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T01:40:17Z","date_published":"2026-08-24T01:40:17Z","id":"https://feed.craftedsignal.io/briefs/2026-08-open5gs-overflow/","summary":"Open5GS 2.8.0 contains a remote heap-based buffer overflow vulnerability (CVE-2026-78156) in the S6a Authentication-Information-Request Handler that can be triggered by manipulating the Visited-PLMN-Id argument.","title":"Heap-based Buffer Overflow in Open5GS S6a Authentication-Information-Request Handler","url":"https://feed.craftedsignal.io/briefs/2026-08-open5gs-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Open5GS","version":"https://jsonfeed.org/version/1.1"}