A missing length check in `ogs_pfcp_subnet_add` function...
High severity
Unreviewed
Published
Jun 18, 2025
to the GitHub Advisory Database
•
Updated Jun 18, 2025
Description
Published by the National Vulnerability Database
Jun 18, 2025
Published to the GitHub Advisory Database
Jun 18, 2025
Last updated
Jun 18, 2025
A missing length check in
ogs_pfcp_subnet_add
function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a local attacker to cause a Buffer Overflow by changing thesession.dnn
field with a value with length greater than 101.References