PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8224 Vuldb CVE debrief

CVE-2026-8224 is a remotely reachable denial-of-service issue in Open5GS PCF, affecting pcf_sess_set_ipv6prefix in /src/pcf/context.c when SmPolicyContextData.ipv6AddressPrefix is manipulated. The supplied record rates the issue MEDIUM severity (CVSS 5.5) and indicates the exploit was publicly disclosed; the CVE was published on 2026-05-10.

Vendor
Vuldb
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-10
Original CVE updated
2026-07-24
Advisory published
2026-05-10
Advisory updated
2026-07-24

Who should care

Operators and defenders running Open5GS, especially environments exposing the PCF component or relying on mobile-core availability. Network teams and incident responders should also pay attention because the impact is service disruption rather than data theft.

Technical summary

The supplied source data describes a flaw in Open5GS PCF’s pcf_sess_set_ipv6prefix function where a crafted SmPolicyContextData.ipv6AddressPrefix value can trigger a denial of service remotely. The NVD-supplied vector indicates a network-reachable attack with no privileges or user interaction required and low availability impact; the supplied CNA metadata maps the issue to CWE-404.

Defensive priority

Medium: remotely triggerable service disruption in a core network component, with public disclosure noted in the supplied record.

Recommended defensive actions

  • Treat Open5GS deployments at version 2.7.7 and earlier as affected until a vendor-fixed release is confirmed.
  • Monitor the upstream Open5GS repository and issue tracker for an official fix or mitigation guidance.
  • Restrict exposure of PCF-facing network paths to trusted peers and minimize unnecessary external reachability.
  • Watch for PCF process crashes, restarts, or abnormal session-policy handling that may indicate attempted triggering.
  • If you cannot upgrade immediately, apply compensating controls such as segmentation, tight ACLs, and enhanced service monitoring.
  • Validate any deployment-specific inputs or policy plumbing that reaches SmPolicyContextData.ipv6AddressPrefix, using vendor guidance rather than ad hoc changes.

Evidence notes

This debrief is based only on the supplied corpus: an NVD modified-feed entry for CVE-2026-8224 and its referenced VulDB/CVE links. The corpus states the affected function, remote DoS impact, version scope (up to 2.7.7), and that the exploit was publicly disclosed; it does not include a vendor advisory or code diff, so no fix version is asserted here.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-8224 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-8224

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-8224 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8224

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.