CVE-2026-10565

low

Description

A security flaw has been discovered in Open5GS up to 2.7.6. The impacted element is the function gmm_state_security_mode of the file src/amf/gmm-sm.c of the component NGAP Handover. Performing a manipulation results in race condition. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.

References

https://vuldb.com/vuln/367672/cti

https://vuldb.com/vuln/367672

https://vuldb.com/submit/818938

https://vuldb.com/cve/CVE-2026-10565

https://github.com/user-attachments/files/27111025/N2-SMC-Concurrent.zip

https://github.com/open5gs/open5gs/pull/4501

https://github.com/open5gs/open5gs/issues/4497

https://github.com/open5gs/open5gs/

Details

Source: Mitre, NVD

Published: 2026-06-02

Updated: 2026-06-02

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:N/AC:H/Au:S/C:N/I:N/A:P

Severity: Low

CVSS v3

Base Score: 3.1

Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

Severity: Low

CVSS v4

Base Score: 2.3

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Severity: Low

EPSS

EPSS: 0.00041