CVE-2026-10116: Open5GS ue-authentications Endpoint ogs-timer.c ogs_sbi_xact_add denial of service
A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogssbixactadd in the library /lib/core/ogs-timer.c of the component ue-authentications Endpoint. Performing a manipulation results in denial of service. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. Applying a patch is the recommended action to fix this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10116?
The severity of CVE-2026-10116 is rated medium with a score of 4.3.
What type of attack does CVE-2026-10116 allow?
CVE-2026-10116 allows for a denial of service attack that can be initiated remotely.
Which component of Open5GS is affected by CVE-2026-10116?
CVE-2026-10116 affects the ue-authentications Endpoint within the Open5GS software.
How do I fix CVE-2026-10116?
To fix CVE-2026-10116, you should update Open5GS to the latest version beyond 2.7.7.
What function is vulnerable in the CVE-2026-10116?
The vulnerable function in CVE-2026-10116 is ogs_sbi_xact_add located in /lib/core/ogs-timer.c.