CVE-2025-15418

PUBLISHED
1/1/2026 1af790b2-7ee1-4545-860a-a788eba489b5

Technical Description

A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function ogs_gtp2_parse_bearer_qos in the library lib/gtp/v2/types.c of the component Bearer QoS IE Length Handler. Performing manipulation results in denial of service. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The patch is named 4e913d21f2c032b187815f063dbab5ebe65fe83a. To fix this issue, it is recommended to deploy a patch.

Affected Products

n/a
Open5GS
2.7.02.7.12.7.2

References

Impact Analysis

Attack Vector Network
Attack Complexity Low
Privileges Required None