{"id":"CVE-2024-14044","summary":"Open5GS Diameter Rx pcrf-rx-path.c pcrf_rx_aar_cb buffer overflow","details":"A vulnerability was identified in Open5GS up to 2.7.1. This issue affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Diameter Rx Handler. The manipulation of the argument num_of_media_component/num_of_sub leads to buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. Upgrading to version 2.7.2 is capable of addressing this issue. The identifier of the patch is 87b4e4535c77ded627cdb6f4e4e2e3ea761f40b7. It is recommended to upgrade the affected component.","modified":"2026-08-14T09:05:43.182764Z","published":"2026-08-12T01:00:14.015Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/14xxx/CVE-2024-14044.json","cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-120"]},"references":[{"type":"WEB","url":"https://github.com/open5gs/open5gs/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/14xxx/CVE-2024-14044.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-14044"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2024-14044"},{"type":"ADVISORY","url":"https://vuldb.com/submit/867117"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/387282"},{"type":"REPORT","url":"https://github.com/open5gs/open5gs/issues/3157"},{"type":"REPORT","url":"https://vuldb.com/vuln/387282/cti"},{"type":"FIX","url":"https://github.com/open5gs/open5gs/commit/87b4e4535c77ded627cdb6f4e4e2e3ea761f40b7"},{"type":"FIX","url":"https://github.com/open5gs/open5gs/releases/tag/v2.7.2"},{"type":"EVIDENCE","url":"https://github.com/open5gs/open5gs/files/15051247/capture.pcap.gz"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open5gs/open5gs","events":[{"introduced":"83e35bb2de7e67646fdba849580184422b10006a"},{"fixed":"87b4e4535c77ded627cdb6f4e4e2e3ea761f40b7"},{"fixed":"43fa4857cce8af6b6ec3c8e3b0cbf99444948f76"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"2.7.0"},{"last_affected":"2.7.0"},{"introduced":"2.7.1"},{"last_affected":"2.7.1"}]}}],"versions":["2.7.0","2.7.1","v2.7.1","v2.7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-14044.json","vanir_signatures_modified":"2026-08-14T09:05:43Z","vanir_signatures":[{"source":"https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76","target":{"file":"src/nrf/nnrf-handler.c","function":"nrf_nnrf_handle_nf_status_update"},"deprecated":false,"digest":{"function_hash":"64878939110562238249368093260391795971","length":3536},"id":"CVE-2024-14044-021355dc","signature_type":"Function","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/87b4e4535c77ded627cdb6f4e4e2e3ea761f40b7","target":{"file":"src/pcrf/pcrf-rx-path.c","function":"pcrf_rx_aar_cb"},"deprecated":false,"digest":{"function_hash":"147604136178718490444537972582417308816","length":8016},"id":"CVE-2024-14044-07b57908"},{"deprecated":false,"digest":{"function_hash":"54820529185091344345021353014457357810","length":4813},"id":"CVE-2024-14044-20392e9b","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76","target":{"file":"src/nrf/nnrf-handler.c","function":"nrf_nnrf_handle_nf_status_subscribe"}},{"target":{"file":"src/pcf/npcf-handler.c","function":"pcf_npcf_policyauthorization_handle_update"},"deprecated":false,"digest":{"function_hash":"18192948449117180226908169912032378018","length":8312},"id":"CVE-2024-14044-25049993","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/87b4e4535c77ded627cdb6f4e4e2e3ea761f40b7"},{"digest":{"line_hashes":["125930618343269423166171477047759652882","215167919317852745312758765163516360590","302795111643205430510295325505330434463","181476369417000736944089116307162828356","235767993398620799680443723605133230991","172267876852941121271025232930121274010"],"threshold":0.9},"id":"CVE-2024-14044-281cabac","signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76","target":{"file":"lib/sbi/nnrf-handler.c"},"deprecated":false},{"digest":{"function_hash":"96134067957720978197926552255752399026","length":1587},"id":"CVE-2024-14044-325188eb","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76","target":{"file":"lib/sbi/nnrf-handler.c","function":"handle_validity_time"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"13212232465897786294742541015130279189","length":10497},"id":"CVE-2024-14044-6b5ffb2b","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/87b4e4535c77ded627cdb6f4e4e2e3ea761f40b7","target":{"file":"src/pcf/npcf-handler.c","function":"pcf_npcf_policyauthorization_handle_create"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/87b4e4535c77ded627cdb6f4e4e2e3ea761f40b7","target":{"file":"src/pcf/npcf-handler.c"},"deprecated":false,"digest":{"line_hashes":["204793006264660394367981042727438485316","311101534145372889206998138529986822772","169088331052639315700976612082013649431","100154423288074907537506363435926965371","193904695077764666821392215825402966788","161000577824216624348762733969298082738","45878280845450755909323669902372540311","140779327977521274742867145399604691902","184661140544202308497491813553030367954","134406121662650797176228911483048292309","320054545811097338444923951181831459634","133575607881647984770037695189742256630","129213306190485830353552047798325018295","204793006264660394367981042727438485316","311101534145372889206998138529986822772","169088331052639315700976612082013649431","100154423288074907537506363435926965371","193904695077764666821392215825402966788","161000577824216624348762733969298082738","45878280845450755909323669902372540311","140779327977521274742867145399604691902","184661140544202308497491813553030367954","134406121662650797176228911483048292309","320054545811097338444923951181831459634","133575607881647984770037695189742256630","129213306190485830353552047798325018295"],"threshold":0.9},"id":"CVE-2024-14044-8cf062f5"},{"source":"https://github.com/open5gs/open5gs/commit/87b4e4535c77ded627cdb6f4e4e2e3ea761f40b7","target":{"file":"src/pcrf/pcrf-rx-path.c"},"deprecated":false,"digest":{"line_hashes":["254453987138905757351857502198900335820","114733116424570344929990833007916507036","158761396504993995495315816566169220376","315510422964043923672904289870634856093","181140169317762666470096375185128915493","135487889361693909411668110705735661852","226029754925402675508241773604952460455","54975882959056192265739782291394804833","174086853351604158555286148280632180752","245880674244821404709820985039620987055","160179689336284063535888151986969254974","32123406595770501607321507717995003868","322079887909876875896333613338611245930"],"threshold":0.9},"id":"CVE-2024-14044-bf3900ad","signature_type":"Line","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76","target":{"file":"src/nrf/nnrf-handler.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["257395929218348314448842538364456807789","128245168593575346110932044743833054792","227731254385837120802644455867923325373","229481775018251413784647459407184981825","161079306334917913917812145518152183846","292392589117498619929147263163282864055","276187307341130075856667759820190175219","158080439368666746858121958480347926241","172267164008105062097219190928411450221","289039494816874545190321298637836742144","13270842352182382920178975182495404891","140733506554091670395272410318360076360","88958982143766265032471606082736208427"]},"id":"CVE-2024-14044-dd1116af","signature_type":"Line"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}