{"id":"CVE-2025-14954","summary":"Open5GS QER/FAR/URR/PDR context.c ogs_pfcp_qer_find_or_add assertion","details":"A vulnerability has been found in Open5GS up to 2.7.6. Affected is the function ogs_pfcp_pdr_find_or_add/ogs_pfcp_far_find_or_add/ogs_pfcp_urr_find_or_add/ogs_pfcp_qer_find_or_add in the library lib/pfcp/context.c of the component QER/FAR/URR/PDR. The manipulation leads to reachable assertion. It is possible to initiate the attack remotely. The attack's complexity is rated as high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 442369dcd964f03d95429a6a01a57ed21f7779b7. Applying a patch is the recommended action to fix this issue.","modified":"2026-08-12T15:13:39.949357Z","published":"2025-12-19T16:02:11.110Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-617"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14954.json","unresolved_ranges":[{"extracted_events":[{"introduced":"2.7.3"},{"last_affected":"2.7.3"},{"introduced":"2.7.4"},{"last_affected":"2.7.4"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://github.com/open5gs/open5gs/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14954.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-14954"},{"type":"ADVISORY","url":"https://vuldb.com/?id.337590"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.716810"},{"type":"REPORT","url":"https://github.com/open5gs/open5gs/issues/4181"},{"type":"REPORT","url":"https://github.com/open5gs/open5gs/issues/4181#issue-3667069101"},{"type":"REPORT","url":"https://github.com/open5gs/open5gs/issues/4181#issuecomment-3615646842"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.337590"},{"type":"FIX","url":"https://github.com/open5gs/open5gs/commit/442369dcd964f03d95429a6a01a57ed21f7779b7"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open5gs/open5gs","events":[{"introduced":"0"},{"fixed":"442369dcd964f03d95429a6a01a57ed21f7779b7"}],"database_specific":{"cpe":"cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.7.5"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["2.7.0","2.7.1","2.7.2","2.7.5","2.7.6","v2.7.2","v2.7.1","v2.7.0","v2.6.6","v2.6.4","v2.6.3","v2.6.2","v2.6.1","v2.4.9","v2.4.8","v2.4.7","v2.4.5","v2.4.4","v2.4.3","v2.4.1","v2.4.0","v2.3.6","v2.3.2","v2.3.0","v2.2.9","v2.2.8","v2.2.7","v2.2.6","v2.2.1","v2.2.0","v2.1.7","v2.1.5","v2.1.4","v2.1.3","v2.1.1","v2.1.0","v2.0.22","v2.0.18","v2.0.0","v1.3.0","v1.2.4","v1.2.3","v1.2.2","v1.2.1","v1.2.0","v1.1.0","v1.0.0","v0.5.2","v0.5.1","v0.5.0","v0.4.4","v0.4.3","v0.4.2","v0.4.1","v0.3.10","v0.3.8","v0.3.6","v0.3.5","v0.3.4","v0.3.3","v0.3.2","v0.3.1","v0.3.0","v0.2.0","v0.1.1","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14954.json","vanir_signatures_modified":"2026-08-12T15:13:39Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"99348471419656350091764651416494565248","length":228},"id":"CVE-2025-14954-0d94d1a8","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/442369dcd964f03d95429a6a01a57ed21f7779b7","target":{"file":"lib/pfcp/context.c","function":"ogs_pfcp_qer_find_or_add"}},{"deprecated":false,"digest":{"function_hash":"99348471419656350091764651416494565248","length":228},"id":"CVE-2025-14954-6e0daa23","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/442369dcd964f03d95429a6a01a57ed21f7779b7","target":{"file":"lib/pfcp/context.c","function":"ogs_pfcp_far_find_or_add"}},{"source":"https://github.com/open5gs/open5gs/commit/442369dcd964f03d95429a6a01a57ed21f7779b7","target":{"file":"lib/pfcp/handler.c"},"deprecated":false,"digest":{"line_hashes":["259291970197500026470746520357610721392","199803091516292476448809222493988811577","180919232541597776046043774683057551274","50608585057955660921075431575047991704","22162246116183490659297086474082581199","124170030514722321650064277416894424365","161905256525036226125030588924592710666","320711779656746574363603578940672477820","175510109846134957050118006066892913804","295890135931699163757092747498147702111","147817652438727747242877400472634449408","215263551927558648941200361127825145441","104323061410415695165795615922597443232","57535600661599625295060740718253124114","75206800299705008042034449471198714119","108229233634851663498039418044864081663","155392759454241145145501003020503724688","36173400567354104693661768995958481755","83044167115267024851882569984385182339","109350331485914057810279805197144444560"],"threshold":0.9},"id":"CVE-2025-14954-773e5de4","signature_type":"Line","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/442369dcd964f03d95429a6a01a57ed21f7779b7","target":{"function":"ogs_pfcp_urr_find_or_add","file":"lib/pfcp/context.c"},"deprecated":false,"digest":{"function_hash":"99348471419656350091764651416494565248","length":228},"id":"CVE-2025-14954-b7df4878"},{"signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/442369dcd964f03d95429a6a01a57ed21f7779b7","target":{"file":"lib/pfcp/context.c","function":"ogs_pfcp_pdr_find_or_add"},"deprecated":false,"digest":{"function_hash":"99348471419656350091764651416494565248","length":228},"id":"CVE-2025-14954-cf502cdc","signature_type":"Function"},{"deprecated":false,"digest":{"line_hashes":["154627695195074138166761654794205512236","131595413227037896249763006367947051227","239341864626613627402317494672046569521","316734446460986720202540776140184306673","255499268516263147423863421951903081755","204590800458089228134615068561881504675","58633263965455771706196646282962598001","104554318124809263498406124537925946471","254484800990544152760403425184859783926","152179835952243477602576433006379010912","30902956542134162793631392988359078171","133356252044353006657796594645328805196","295259385680568296896230624412647065009","49421976990443233639569547460018554539","294037414799643470258222285797691779996","210423505155969253819024677925826313789"],"threshold":0.9},"id":"CVE-2025-14954-ed048a32","signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/442369dcd964f03d95429a6a01a57ed21f7779b7","target":{"file":"lib/pfcp/context.c"}},{"target":{"file":"lib/pfcp/handler.c","function":"ogs_pfcp_handle_create_pdr"},"deprecated":false,"digest":{"function_hash":"226016123465411250321008823215246105336","length":8388},"id":"CVE-2025-14954-f669db2f","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/442369dcd964f03d95429a6a01a57ed21f7779b7"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}