Open5GS MME versions <= 2.6.4 contain a reachable assertion in the UE Context Release Request
packet handler. A packet containing an invalid MME_UE_S1AP_ID
field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Open5gs | Open5gs | * | 2.6.4 (including) |