{"id":"CVE-2026-78157","summary":"Open5GS Rx AA-Request pcrf-rx-path.c pcrf_rx_aar_cb out-of-bounds","details":"A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Request Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. The patch is named c18dc6938bf63cc7374315d3dca303d92066e746. To fix this issue, it is recommended to deploy a patch.","modified":"2026-08-27T19:34:14.929760Z","published":"2026-08-24T00:00:13.451Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78157.json"},"references":[{"type":"WEB","url":"https://github.com/open5gs/open5gs/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78157.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78157"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-78157"},{"type":"ADVISORY","url":"https://vuldb.com/submit/882953"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/394540"},{"type":"REPORT","url":"https://github.com/open5gs/open5gs/issues/4663"},{"type":"REPORT","url":"https://vuldb.com/vuln/394540/cti"},{"type":"FIX","url":"https://github.com/open5gs/open5gs/commit/c18dc6938bf63cc7374315d3dca303d92066e746"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open5gs/open5gs","events":[{"introduced":"157f611a530e292e40ec50f9d23f0ef5d4fcd6a6"},{"fixed":"c18dc6938bf63cc7374315d3dca303d92066e746"}],"database_specific":{"extracted_events":[{"introduced":"2.8.0"},{"last_affected":"2.8.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["2.8.0","v2.8.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78157.json","vanir_signatures_modified":"2026-08-27T19:34:14Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/c18dc6938bf63cc7374315d3dca303d92066e746","target":{"file":"src/pcrf/pcrf-rx-path.c"},"deprecated":false,"digest":{"line_hashes":["32334434667660954560781523960294591284","336021117126522999659070877067204740092","72078626147220255317365003083767561028","313649866467712591899567430556988528224","184867069493659557667224217419499389584","175726008871943307600134519706152339744","332788874488267496362048765756972197372","116609706633753084511655914902245708207","321993816506930856306479791757347281999","163549631563018275337154807791221105118","126331574493250423621060034636648494879","85686689274029915160107750907583488239","325680419507324727928681861658193305038","195674996205522537557862521428554537177","202493617117614631758617871545169304206","205362084833976597825328710100423202574","223133408794077750253332133473232634048","90143803944926730835373437567003479967","122660507281825243231189972401186182449","108587633537507210242609878158511307392"],"threshold":0.9},"id":"CVE-2026-78157-41c02183","signature_type":"Line"},{"digest":{"function_hash":"3650037655332043584086096641845316749","length":10398},"id":"CVE-2026-78157-f39c997f","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/c18dc6938bf63cc7374315d3dca303d92066e746","target":{"file":"src/pcrf/pcrf-rx-path.c","function":"pcrf_rx_aar_cb"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P"}]}