PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-92417 Open5GS CVE debrief

A vulnerability was found in Open5GS up to 2.8.0, specifically in the function ogs_pfcp_parse_volume_measurement within the library lib/pfcp/types.c of the PFCP Handler component. This vulnerability results in a null pointer dereference and can be exploited remotely. A patch, identified as 8f07b507b78ff94776f2cd49276eb116ed93d7f2, is available to remediate this issue.

Vendor
Open5GS
Product
Open5GS
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-09-22
Advisory published
2026-09-16
Advisory updated
2026-09-22

Who should care

Defenders responsible for Open5GS deployments should assess exposure and apply the patch to remediate the vulnerability. This includes Open5GS operators, security teams, and vulnerability management teams who need to verify Open5GS versions and configurations to ensure they are not vulnerable. IT and network security personnel responsible for maintaining Open5GS installations should prioritize patch application and verify the integrity of their deployments

Why it matters

CVE-2026-92417 is a null pointer dereference vulnerability in Open5GS up to 2.8.0 that can be exploited remotely. Defenders should assess exposure, apply the patch, and verify Open5GS versions to ensure they are not vulnerable.

  • Remote exploitation of the vulnerability
  • Potential disruption of service due to null pointer dereference
  • Need for patch application to remediate the issue
  • Verification of Open5GS version to ensure it is not vulnerable

Technical summary

The vulnerability affects Open5GS up to version 2.8.0 and is located in the ogs_pfcp_parse_volume_measurement function within the lib/pfcp/types.c library of the PFCP Handler component. The vulnerability leads to a null pointer dereference and can be exploited remotely, potentially disrupting service. The patch 8f07b507b78ff94776f2cd49276eb116ed93d7f2 should be applied to remediate the issue. Affected deployments should be identified and verified for vulnerability through detailed configuration reviews and version checks.

Defensive priority

Apply the patch to remediate the null pointer dereference vulnerability in Open5GS up to 2.8.0.

Recommended defensive actions

  • Apply the patch 8f07b507b78ff94776f2cd49276eb116ed93d7f2 to remediate the vulnerability
  • Verify the version of Open5GS is not vulnerable
  • Monitor for potential exploitation attempts
  • Review Open5GS configurations for potential exposure
  • Conduct a thorough risk assessment for Open5GS deployments
  • Implement compensating controls for exposed systems while remediation is scheduled
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. However, the exact scope of affected deployments and potential impact require further verification and detailed review of Open5GS configurations and patch application status. Additional information from other sources may be necessary to fully understand the vulnerability's impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-92417 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-92417

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-92417 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92417

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.