CVE-2026-82590

medium

Description

A weakness has been identified in Open5GS up to 2.7.7. The affected element is the function smf_nudm_sdm_handle_get of the file src/smf/nudm-handler.c of the component SMF. Executing a manipulation of the argument preemptCap can lead to reachable assertion. The attack may be launched remotely. Upgrading to version 2.8.0 is sufficient to fix this issue. This patch is called 4554405f29bffd7562abedbee63484825bd90cd5. You should upgrade the affected component.

References

https://vuldb.com/vuln/397085/cti

https://vuldb.com/vuln/397085

https://vuldb.com/submit/891893

https://vuldb.com/cve/CVE-2026-82590

https://github.com/open5gs/open5gs/releases/tag/v2.8.0

https://github.com/open5gs/open5gs/issues/4455

https://github.com/open5gs/open5gs/commit/4554405f29bffd7562abedbee63484825bd90cd5

https://github.com/open5gs/open5gs/

Details

Source: Mitre, NVD

Published: 2026-08-30

Updated: 2026-08-30

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Severity: Medium

CVSS v4

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Severity: Medium