CVE-2026-108102Medium· 5.3▾ SunlitOpen5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_volume_measurement() in lib/pfcp/types.c that allows remote unauthenticated attackers to read past IE buffers. Attackers can send a PFCP Session Rep…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_volume_measurement() in lib/pfcp/types.c that allows remote unauthenticated attackers to read past IE buffers. Attackers can send a PFCP Session Report Request to the SMF on UDP port 8805 with a short, all-flags Volume Measurement IE, reading up to 48 bytes and potentially crashing the SMF.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-55092Medium· 5.3In Eclipse Foundation NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_option_process() when processing an IPv4 packet with the timestamp option.
CVE-2025-11840Low· 3.3A weakness has been identified in GNU Binutils 2.45
CVE-2025-55086Critical· 9.8In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked index extracting the server DUID from the server reply
CVE-2025-11413Low· 3.3A vulnerability was found in GNU Binutils 2.45
CVE-2025-11414Low· 3.3A vulnerability was determined in GNU Binutils 2.45
CVE-2025-11412Low· 3.3A vulnerability has been found in GNU Binutils 2.45