A missing length check in `ogs_pfcp_dev_add` function...
High severity
Unreviewed
Published
Jun 18, 2025
to the GitHub Advisory Database
•
Updated Jun 20, 2025
Description
Published by the National Vulnerability Database
Jun 18, 2025
Published to the GitHub Advisory Database
Jun 18, 2025
Last updated
Jun 20, 2025
A missing length check in
ogs_pfcp_dev_add
function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a local attacker to cause a Buffer Overflow by changing thesession.dev
field with a value with length greater than 32.References