{"id":"CVE-2024-14042","summary":"Open5GS Diameter S6a hss-s6a-path.c hss_ogs_diam_s6a_ulr_cb stack-based overflow","details":"A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr_cb of the file src/hss/hss-s6a-path.c of the component Diameter S6a Interface. Performing a manipulation of the argument os.len results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 2.7.2 is able to mitigate this issue. The patch is named e89aa79efe629ae90f59dcdf8847c117d9a7da86. It is suggested to upgrade the affected component.","modified":"2026-08-14T09:05:42.688814Z","published":"2026-08-11T19:15:09.514Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-121"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/14xxx/CVE-2024-14042.json"},"references":[{"type":"WEB","url":"https://github.com/open5gs/open5gs/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/14xxx/CVE-2024-14042.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-14042"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2024-14042"},{"type":"ADVISORY","url":"https://vuldb.com/submit/867105"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/387280"},{"type":"REPORT","url":"https://github.com/open5gs/open5gs/issues/3155"},{"type":"REPORT","url":"https://vuldb.com/vuln/387280/cti"},{"type":"FIX","url":"https://github.com/open5gs/open5gs/commit/e89aa79efe629ae90f59dcdf8847c117d9a7da86"},{"type":"FIX","url":"https://github.com/open5gs/open5gs/releases/tag/v2.7.2"},{"type":"EVIDENCE","url":"https://github.com/open5gs/open5gs/files/15051218/capture.pcap.gz"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open5gs/open5gs","events":[{"introduced":"83e35bb2de7e67646fdba849580184422b10006a"},{"fixed":"e89aa79efe629ae90f59dcdf8847c117d9a7da86"},{"fixed":"43fa4857cce8af6b6ec3c8e3b0cbf99444948f76"}],"database_specific":{"extracted_events":[{"introduced":"2.7.0"},{"last_affected":"2.7.0"},{"introduced":"2.7.1"},{"last_affected":"2.7.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["2.7.0","2.7.1","v2.7.1","v2.7.0"],"database_specific":{"vanir_signatures":[{"target":{"file":"src/nrf/nnrf-handler.c","function":"nrf_nnrf_handle_nf_status_update"},"deprecated":false,"digest":{"function_hash":"64878939110562238249368093260391795971","length":3536},"id":"CVE-2024-14042-021355dc","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/e89aa79efe629ae90f59dcdf8847c117d9a7da86","target":{"file":"src/hss/hss-s6a-path.c","function":"hss_ogs_diam_s6a_ulr_cb"},"deprecated":false,"digest":{"length":5934,"function_hash":"137852393407895265767706288030418867306"},"id":"CVE-2024-14042-1fe2c584"},{"source":"https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76","target":{"file":"src/nrf/nnrf-handler.c","function":"nrf_nnrf_handle_nf_status_subscribe"},"deprecated":false,"digest":{"function_hash":"54820529185091344345021353014457357810","length":4813},"id":"CVE-2024-14042-20392e9b","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["165690721616426534099534328523936116807","261243168294521985828275779675784209436","58800936853138522851815033994950632698","292292056152113626468784833482101536932","165690721616426534099534328523936116807","104451065855420431323085799889312635048","273600911875957829853736629726786116237","232808879163079335822956491958052534515"]},"id":"CVE-2024-14042-2655f6fa","signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/e89aa79efe629ae90f59dcdf8847c117d9a7da86","target":{"file":"src/hss/hss-s6a-path.c"}},{"deprecated":false,"digest":{"line_hashes":["125930618343269423166171477047759652882","215167919317852745312758765163516360590","302795111643205430510295325505330434463","181476369417000736944089116307162828356","235767993398620799680443723605133230991","172267876852941121271025232930121274010"],"threshold":0.9},"id":"CVE-2024-14042-281cabac","signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76","target":{"file":"lib/sbi/nnrf-handler.c"}},{"signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76","target":{"function":"handle_validity_time","file":"lib/sbi/nnrf-handler.c"},"deprecated":false,"digest":{"function_hash":"96134067957720978197926552255752399026","length":1587},"id":"CVE-2024-14042-325188eb","signature_type":"Function"},{"signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/e89aa79efe629ae90f59dcdf8847c117d9a7da86","target":{"file":"src/hss/hss-s6a-path.c","function":"hss_ogs_diam_s6a_air_cb"},"deprecated":false,"digest":{"function_hash":"195088638377963736100241869331406785003","length":5999},"id":"CVE-2024-14042-78f3ead2","signature_type":"Function"},{"deprecated":false,"digest":{"line_hashes":["257395929218348314448842538364456807789","128245168593575346110932044743833054792","227731254385837120802644455867923325373","229481775018251413784647459407184981825","161079306334917913917812145518152183846","292392589117498619929147263163282864055","276187307341130075856667759820190175219","158080439368666746858121958480347926241","172267164008105062097219190928411450221","289039494816874545190321298637836742144","13270842352182382920178975182495404891","140733506554091670395272410318360076360","88958982143766265032471606082736208427"],"threshold":0.9},"id":"CVE-2024-14042-dd1116af","signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76","target":{"file":"src/nrf/nnrf-handler.c"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-14042.json","vanir_signatures_modified":"2026-08-14T09:05:42Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}