{"id":"CVE-2026-75894","title":"In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash and remote denial of service.","summary":"In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash and remote denial of service.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-617"],"vendor":"Osmocom","product":"osmo-iuh","affected":["osmo-iuh >= 0.1.0 < 1.8.0"],"published":"2026-09-18","updated":"2026-09-21","sourceUpdated":"2026-09-21T19:17:10.070","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-75894","references":[{"url":"https://cgit.osmocom.org/osmo-iuh/commit/?id=f06967126f486bcb185ccf3d1a8f9bc02c4da1f6","label":"74b3a70d-cca6-4d34-9789-e83b222ae3be"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-21T18:25:51.366823Z"},"epss":0.00169,"epssPercentile":0.06582,"ingestedAt":"2026-09-18T19:49:30.581Z","slug":"CVE-2026-75894","body":"## Overview\n\nIn osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash and remote denial of service.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":208723,"id":"CVE-2026-75894","ts":1790016707702,"field":"cvss","old":null,"new":"7.5"},{"seq":208722,"id":"CVE-2026-75894","ts":1790016707702,"field":"severity","old":"none","new":"high"}]}