{"id":"CVE-2026-82587","summary":"Open5GS AMF namf-handler.c amf_namf_comm_decode_ue_mm_context_list memory corruption","details":"A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function amf_namf_comm_decode_ue_mm_context_list of the file src/amf/namf-handler.c of the component AMF. This manipulation of the argument ueContext.mmContextList[*].allowedNssai causes memory corruption. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.8.0 is able to resolve this issue. Patch name: abf8a836564b966b5141110fc25ed413c4f17522. It is recommended to upgrade the affected component.","modified":"2026-09-01T08:20:14.843898Z","published":"2026-08-30T19:00:11.238Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82587.json","unresolved_ranges":[{"extracted_events":[{"introduced":"2.7.3"},{"last_affected":"2.7.3"},{"introduced":"2.7.4"},{"last_affected":"2.7.4"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://github.com/open5gs/open5gs/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82587.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82587"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-82587"},{"type":"ADVISORY","url":"https://vuldb.com/submit/891890"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/397082"},{"type":"REPORT","url":"https://github.com/open5gs/open5gs/issues/4398"},{"type":"REPORT","url":"https://vuldb.com/vuln/397082/cti"},{"type":"FIX","url":"https://github.com/open5gs/open5gs/commit/abf8a836564b966b5141110fc25ed413c4f17522"},{"type":"FIX","url":"https://github.com/open5gs/open5gs/releases/tag/v2.8.0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open5gs/open5gs","events":[{"introduced":"83e35bb2de7e67646fdba849580184422b10006a"},{"fixed":"abf8a836564b966b5141110fc25ed413c4f17522"},{"fixed":"157f611a530e292e40ec50f9d23f0ef5d4fcd6a6"}],"database_specific":{"extracted_events":[{"introduced":"2.7.0"},{"last_affected":"2.7.0"},{"introduced":"2.7.1"},{"last_affected":"2.7.1"},{"introduced":"2.7.2"},{"last_affected":"2.7.2"},{"introduced":"2.7.5"},{"last_affected":"2.7.5"},{"introduced":"2.7.6"},{"last_affected":"2.7.6"},{"introduced":"2.7.7"},{"last_affected":"2.7.7"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["2.7.0","2.7.1","2.7.2","2.7.5","2.7.6","2.7.7","v2.7.7","v2.7.2","v2.7.1","v2.7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82587.json","vanir_signatures_modified":"2026-09-01T08:20:14Z","vanir_signatures":[{"target":{"file":"tests/common/context.c","function":"test_db_insert_ue"},"deprecated":false,"digest":{"function_hash":"269989511999798805408776959487049030916","length":1584},"id":"CVE-2026-82587-3271f6be","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/157f611a530e292e40ec50f9d23f0ef5d4fcd6a6"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/abf8a836564b966b5141110fc25ed413c4f17522","target":{"file":"src/amf/namf-handler.c"},"deprecated":false,"digest":{"line_hashes":["32624273255323015896282218712730651780","269418364994249133721482499013174656712","70513220199183723314677830788543090892","90191518991051014943986887335678206251","185396313955445543450323814049250824170","149941259905066062322469231625204343179","103247220534627767700077487525094035669","29303917820747973906746935226461529455","119789832489319145664228829058742736576","133845146168819597657409658742065068699","273612018788393917395043162080995503322","300690317107650670263651140325137846768","8740063985184529229216439711318442528","59009065244673768044853970526938039426","215830066465972346022758022115923576204","118746868935892064350249571962605821600","162636344835490759181077362855999748171","234993270076391098544098892226544281124","103376363310613786737424862814319541544","161905493284587823764952895175714406424","234015935082240881235914326215015140090","31808813619795672022824687981343615300","262386686113085773093363483488504082643","150498433710260714326985373084842982134","13006089044630866627790724904770121517","135466957327566345771717607194198705341","184661692560590323475933194822648711580","38289079468759261414084509245801468096","316841761073453113817585358358794882180","117702163224296695803301152537087953125","204725453015015271374367286754688317287","5026158499799704365384699521884544121","133036800816050407058623071056822730399","49384332299720043576333651580227166720","88473020490284142938987022963357622039","315127271648338547728087275757675359857","266485964761552269272878857368715515669","91590701461387566658242826366221696283","120011451435709055489062286639234581579","329994388303430576953369716656446392789","81621985662547771383488155092897987122","68791127734877522708058677441379920611","63767502405995301198464899523895143593","161935723526410214872025504250906874109","133972049007008520577402299129740412155","36982209176391161307463330194475091839","273493326748257898198089126934902737805","331692645682707926540912311877852917030","32748914243737176240193699720791767945","133012729491519867107241556682046181539","5614052840744975786950491795249542679","69716754562065699893024540376353996903","9406519180075802896564017068407514578","26391318315777892397925164988007745131","90600654126676577137092117272546309576","291339846538732969259917660037031828509","38794283339239228603786551507745538762","146368348362503263940020477877555812660","174246635915680734016944018074778439597","204335095691864087387998255176629147321","182054546297360644078535055546012221571","32743505682085116261786372557098451917","303558393108593770965048109240356289350","18773032717020675700205625959267903317","297360095028104587686121580237550463364","339845278300110609419777098246139022890","54949253383480602926729673858968665327","193354211315093418142771574903464001828","152447614657366535842807839375233714178"],"threshold":0.9},"id":"CVE-2026-82587-55a8d127"},{"digest":{"function_hash":"107437639792314003364978050113291534728","length":9276},"id":"CVE-2026-82587-6dc659cc","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/abf8a836564b966b5141110fc25ed413c4f17522","target":{"file":"src/amf/namf-handler.c","function":"amf_namf_comm_handle_n1_n2_message_transfer"},"deprecated":false},{"digest":{"line_hashes":["89714231803210300349029899902762723787","216254685653352833187689837665217332085","335816294610166792862992334015549679232","45647755495410842334388829683427303171","300040392950149666439873900614186251387","44008193511893640358241655468743290907","101891682352354475027959434028209490796","45647755495410842334388829683427303171"],"threshold":0.9},"id":"CVE-2026-82587-79321a86","signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/157f611a530e292e40ec50f9d23f0ef5d4fcd6a6","target":{"file":"tests/common/context.c"},"deprecated":false},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/abf8a836564b966b5141110fc25ed413c4f17522","target":{"file":"src/amf/namf-handler.c","function":"amf_namf_comm_handle_ue_context_transfer_request"},"deprecated":false,"digest":{"function_hash":"128680602490449212561049132182482934036","length":3578},"id":"CVE-2026-82587-98a6c519"},{"deprecated":false,"digest":{"length":2547,"function_hash":"300343677791312392452427718182201626191"},"id":"CVE-2026-82587-9f20fda7","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/abf8a836564b966b5141110fc25ed413c4f17522","target":{"file":"src/amf/namf-handler.c","function":"amf_namf_comm_handle_registration_status_update_request"}},{"deprecated":false,"digest":{"function_hash":"40941568310527533512878628803719256529","length":1008},"id":"CVE-2026-82587-e178de90","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/abf8a836564b966b5141110fc25ed413c4f17522","target":{"file":"src/amf/namf-handler.c","function":"update_ambr"}},{"deprecated":false,"digest":{"function_hash":"322431929163089881254695625748933196963","length":1054},"id":"CVE-2026-82587-f1f66edd","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/abf8a836564b966b5141110fc25ed413c4f17522","target":{"file":"src/amf/namf-handler.c","function":"amf_namf_comm_decode_ue_mm_context_list"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}