CVE-2026-10114: Open5GS Shared NF-profile nnrf-handler.c handle_scp_info out-of-bounds write
A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function handlescpinfo in the library lib/sbi/nnrf-handler.c of the component Shared NF-profile Parser. This manipulation causes out-of-bounds write. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. To fix this issue, it is recommended to deploy a patch.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10114?
The severity of CVE-2026-10114 is medium, rated at 4.3 on the CVSS scale.
How do I fix CVE-2026-10114?
To fix CVE-2026-10114, upgrade to Open5GS version 2.7.8 or later where the vulnerability has been patched.
What is the impact of CVE-2026-10114?
CVE-2026-10114 can lead to an out-of-bounds write, potentially allowing remote attackers to exploit the weakness.
In which component of Open5GS does CVE-2026-10114 occur?
CVE-2026-10114 occurs in the Shared NF-profile Parser within the function handle_scp_info of the file nnrf-handler.c.
Is CVE-2026-10114 remotely exploitable?
Yes, CVE-2026-10114 can be exploited remotely, making it a significant security concern.