PatchSiren

Openairinterface CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Openairinterface CVE published 2026-04-08

CVE-2026-30080

OpenAirInterface v2.2.0 has a vulnerability where it accepts Security Mode Complete without any integrity protection. The configuration supports integrity NIA1 and NIA2, but if a user equipment (UE) sends an initial registration request with only security capability IA0, OpenAirInterface accepts and proceeds. This downgrade in security context can lead to the possibility of replay attacks. The vulnerabili [truncated]

HIGH OpenAirInterface CVE published 2026-04-08

CVE-2026-30075

CVE-2026-30075 is a Buffer Overflow vulnerability in OpenAirInterface Version 2.2.0. The vulnerability occurs in processing UplinkNASTransport containing Authentication Response with an oversized NAS PDU, which can cause the AUSF component to crash, leading to Denial of Services (DoS). This vulnerability can prohibit users from further registration and verification. The vulnerability has a CVSS score of 7 [truncated]