{"id":"CVE-2024-14043","summary":"Open5GS Diameter S6a mme-fd-path.c mme_s6a_subscription_data_from_avp heap-based overflow","details":"A vulnerability was determined in Open5GS up to 2.7.1. This vulnerability affects the function mme_s6a_subscription_data_from_avp of the file src/mme/mme-fd-path.c of the component Diameter S6a Interface. Executing a manipulation of the argument msisdn_len can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.7.2 is able to resolve this issue. This patch is called 7ea82cb87bb65c3694d8d7c7a5efed1c4d3c9304. Upgrading the affected component is recommended.","modified":"2026-08-14T09:05:47.579055Z","published":"2026-08-11T23:15:14.244Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/14xxx/CVE-2024-14043.json"},"references":[{"type":"WEB","url":"https://github.com/open5gs/open5gs/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/14xxx/CVE-2024-14043.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-14043"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2024-14043"},{"type":"ADVISORY","url":"https://vuldb.com/submit/867106"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/387281"},{"type":"REPORT","url":"https://github.com/open5gs/open5gs/issues/3156"},{"type":"REPORT","url":"https://vuldb.com/vuln/387281/cti"},{"type":"FIX","url":"https://github.com/open5gs/open5gs/commit/7ea82cb87bb65c3694d8d7c7a5efed1c4d3c9304"},{"type":"FIX","url":"https://github.com/open5gs/open5gs/releases/tag/v2.7.2"},{"type":"EVIDENCE","url":"https://github.com/open5gs/open5gs/files/15051238/capture.pcap.gz"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open5gs/open5gs","events":[{"introduced":"83e35bb2de7e67646fdba849580184422b10006a"},{"fixed":"7ea82cb87bb65c3694d8d7c7a5efed1c4d3c9304"},{"fixed":"43fa4857cce8af6b6ec3c8e3b0cbf99444948f76"}],"database_specific":{"extracted_events":[{"introduced":"2.7.0"},{"last_affected":"2.7.0"},{"introduced":"2.7.1"},{"last_affected":"2.7.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["2.7.0","2.7.1","v2.7.1","v2.7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-14043.json","vanir_signatures_modified":"2026-08-14T09:05:47Z","vanir_signatures":[{"id":"CVE-2024-14043-021355dc","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76","target":{"file":"src/nrf/nnrf-handler.c","function":"nrf_nnrf_handle_nf_status_update"},"deprecated":false,"digest":{"function_hash":"64878939110562238249368093260391795971","length":3536}},{"id":"CVE-2024-14043-0f290c9f","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/7ea82cb87bb65c3694d8d7c7a5efed1c4d3c9304","target":{"file":"src/mme/mme-fd-path.c","function":"mme_s6a_subscription_data_from_avp"},"deprecated":false,"digest":{"function_hash":"302339452956253238217977334686794779846","length":10137}},{"deprecated":false,"digest":{"function_hash":"54820529185091344345021353014457357810","length":4813},"id":"CVE-2024-14043-20392e9b","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76","target":{"file":"src/nrf/nnrf-handler.c","function":"nrf_nnrf_handle_nf_status_subscribe"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/7ea82cb87bb65c3694d8d7c7a5efed1c4d3c9304","target":{"file":"src/mme/mme-fd-path.c","function":"mme_s6a_aia_cb"},"deprecated":false,"digest":{"length":6293,"function_hash":"114907022204079731042605297281080486640"},"id":"CVE-2024-14043-2152ab7a"},{"deprecated":false,"digest":{"line_hashes":["125930618343269423166171477047759652882","215167919317852745312758765163516360590","302795111643205430510295325505330434463","181476369417000736944089116307162828356","235767993398620799680443723605133230991","172267876852941121271025232930121274010"],"threshold":0.9},"id":"CVE-2024-14043-281cabac","signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76","target":{"file":"lib/sbi/nnrf-handler.c"}},{"signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76","target":{"file":"lib/sbi/nnrf-handler.c","function":"handle_validity_time"},"deprecated":false,"digest":{"function_hash":"96134067957720978197926552255752399026","length":1587},"id":"CVE-2024-14043-325188eb","signature_type":"Function"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/7ea82cb87bb65c3694d8d7c7a5efed1c4d3c9304","target":{"file":"src/mme/mme-fd-path.c"},"deprecated":false,"digest":{"line_hashes":["94415402330655881639683924850618469195","89407614634011689381690007396400003511","70164774428275322249878497224992129292","277209773426661712010605084170326054100","5642509417222277407254531619819053616","185361630637494499522736085149356864869","147900290054452269710342488882471075056","301781377033304152121774470010005777640","146223179387980959890539553442619891721","319706652496871922331927121062053814440","320103224776515270121967530419719144905","291326593272578635053792875622934973833","234691435015206121196059751831620218372","240210752376958008494786530858519311971","301914434538318616846869165104638418165","122932490630194918718495580123127327550","268679122174258766628799800316602917767","190373193714982846936551601863830474048","251151822047589099557017043210099521891","22126027595949709474652751371976058052","220943372616978755681624913502087212545","162829214181350669556374866302335548571","298717738428384580301374838153008359928","316708157350687804801423089823794158435","339925324060668589454239764665551036253","16758358471593897767230381462488835276","37516814748226144390402018140704954239","241994314542026332312309087373223695960","195099837081947939128479455531502956685","14490509585830314980863610718762470132","256245688403455696141513971860539470931","287929114085365061593172116725114648153","309574630253217721071601219524373634551","157433723045245156417875906620511280253"],"threshold":0.9},"id":"CVE-2024-14043-34868d27"},{"source":"https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76","target":{"file":"src/nrf/nnrf-handler.c"},"deprecated":false,"digest":{"line_hashes":["257395929218348314448842538364456807789","128245168593575346110932044743833054792","227731254385837120802644455867923325373","229481775018251413784647459407184981825","161079306334917913917812145518152183846","292392589117498619929147263163282864055","276187307341130075856667759820190175219","158080439368666746858121958480347926241","172267164008105062097219190928411450221","289039494816874545190321298637836742144","13270842352182382920178975182495404891","140733506554091670395272410318360076360","88958982143766265032471606082736208427"],"threshold":0.9},"id":"CVE-2024-14043-dd1116af","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}