CVE-2026-108102 Open5GS 堆越界读取漏洞
影响远程未认证攻击者可读取越界内存并可能使 SMF 崩溃
Open5GS 2.8.0 及之前版本的 lib/pfcp/types.c 中 ogs_pfcp_parse_volume_measurement() 函数存在堆越界读取漏洞。攻击者可通过向 SMF 的 UDP 8805 端口发送构造的 PFCP Session Report Request 报文触发该漏洞。
影响范围
Open5GS 2.8.0 及之前版本(through 2.8.0),具体受影响版本范围以官方公告为准。
漏洞详情
该漏洞属于堆越界读取(CWE-125),成因是解析 Volume Measurement IE 时未充分校验缓冲区长度。当攻击者发送带有全部标志位但长度很短的 Volume Measurement IE 时,解析函数会读取超出 IE 缓冲区最多 48 字节的内存。攻击者无需认证即可通过 UDP 8805 端口远程触发,可能导致 SMF 进程崩溃。
利用条件与风险
利用前提是攻击者能向 SMF 的 UDP 8805 端口发送 PFCP 报文,无需认证。实战中可造成 SMF 拒绝服务,并可能泄露少量堆内存信息,CVSS 5.3 属中危。
修复建议
建议关注 Open5GS 官方发布的修复版本并升级;临时缓解措施包括限制 UDP 8805 端口的访问来源、仅允许可信网元通信,或部署流量过滤规则拦截异常 PFCP 报文。
Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_volume_measurement() in lib/pfcp/types.c that allows remote unauthenticated attackers to read past IE buffers. Attackers can send a PFCP Session Report Request to the SMF on UDP port 8805 with a short, all-flags Volume Measurement IE, reading up to 48 bytes and potentially crashing the SMF.