{"id":"CVE-2026-90707","summary":"Open5GS Old AMF Discovery Fallback nnrf-handler.c amf_nnrf_try_old_amf_discovery_fallback use after free","details":"A security flaw has been discovered in Open5GS up to 2.7.x. Affected is the function amf_nnrf_try_old_amf_discovery_fallback of the file src/amf/nnrf-handler.c of the component Old AMF Discovery Fallback. The manipulation of the argument discovery_option results in use after free. The attack may be performed from remote. The patch is identified as ddd683a35f8aaac2b7b9884a24cd53bddfc65238. Applying a patch is advised to resolve this issue.","modified":"2026-09-17T08:02:16.119047Z","published":"2026-09-14T10:45:08.438Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-416"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90707.json","unresolved_ranges":[{"extracted_events":[{"introduced":"2.5"},{"last_affected":"2.5"},{"introduced":"2.6"},{"last_affected":"2.6"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://github.com/open5gs/open5gs/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90707.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90707"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-90707"},{"type":"ADVISORY","url":"https://vuldb.com/submit/918267"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/403249"},{"type":"REPORT","url":"https://vuldb.com/vuln/403249/cti"},{"type":"FIX","url":"https://github.com/open5gs/open5gs/commit/ddd683a35f8aaac2b7b9884a24cd53bddfc65238"},{"type":"FIX","url":"https://github.com/open5gs/open5gs/pull/4698"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open5gs/open5gs","events":[{"introduced":"23c57b84b893f585908c95a1d7d94a8e5b484445"},{"fixed":"ddd683a35f8aaac2b7b9884a24cd53bddfc65238"}],"database_specific":{"extracted_events":[{"introduced":"2.0"},{"last_affected":"2.0"},{"introduced":"2.1"},{"last_affected":"2.1"},{"introduced":"2.2"},{"last_affected":"2.2"},{"introduced":"2.3"},{"last_affected":"2.3"},{"introduced":"2.4"},{"last_affected":"2.4"},{"introduced":"2.7"},{"last_affected":"2.7"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["2.0","2.1","2.2","2.3","2.4","2.7","v2.8.0","v2.7.7","v2.7.2","v2.7.1","v2.7.0","v2.6.6","v2.6.4","v2.6.3","v2.6.2","v2.6.1","v2.4.9","v2.4.8","v2.4.7","v2.4.5","v2.4.4","v2.4.3","v2.4.1","v2.4.0","v2.3.6","v2.3.2","v2.3.0","v2.2.9","v2.2.8","v2.2.7","v2.2.6","v2.2.1","v2.2.0","v2.1.7","v2.1.5","v2.1.4","v2.1.3","v2.1.1","v2.1.0","v2.0.22","v2.0.18","v2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90707.json","vanir_signatures_modified":"2026-09-17T08:02:16Z","vanir_signatures":[{"id":"CVE-2026-90707-0a548235","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/ddd683a35f8aaac2b7b9884a24cd53bddfc65238","target":{"file":"src/amf/nnrf-handler.c","function":"amf_nnrf_handle_failed_amf_discovery"},"deprecated":false,"digest":{"function_hash":"145325533730271639697057628044301582202","length":1947}},{"target":{"file":"src/amf/nnrf-handler.c"},"deprecated":false,"digest":{"line_hashes":["81482809240923113474767271872609296911","54649887621598908665781293546502726004","243555174681841255669163456396942241265","262252388139781146943512055351004589490","255588745852037001143230161728789009773","62620928685624160503499001793180048258","17417742761614477236284533499598251525","330315398903319499296713996318655483474","139273765223866279017235078168543792550","284999848277181422916562762239385689754","11514335949590486800677058128240709420","94439711860204125915950974857503625477","190798079971714899547258147245192814452","3156176311557680188467543572093684406","212288291750472162927199326755419730399","318732728975664944474187625382235539740","316308549655715049900646722873140983284","34190236449631450621439303596061165051","188975690839983670783043191328237441673","142875368198450374281672274204628160912","78164890412884877575140924031150555313","85578689364857064332318940093782963527","134054206212726627938836788013098814241","223243837880295071313518321168022997790","148705633158732011269672277409463911272","172218646339745607786836244800839323889","202271290071617596609676312378149818938","101526491535867951163620436879535362903","5194696107461444847842247984448478925","291445330050680751299597861862765629618","188975690839983670783043191328237441673","142875368198450374281672274204628160912"],"threshold":0.9},"id":"CVE-2026-90707-b7e8b873","signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/ddd683a35f8aaac2b7b9884a24cd53bddfc65238"},{"signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/ddd683a35f8aaac2b7b9884a24cd53bddfc65238","target":{"file":"src/amf/nnrf-handler.c","function":"amf_nnrf_try_old_amf_discovery_fallback"},"deprecated":false,"digest":{"length":607,"function_hash":"128162418276963409374489795537792784550"},"id":"CVE-2026-90707-c13bd80b","signature_type":"Function"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/ddd683a35f8aaac2b7b9884a24cd53bddfc65238","target":{"file":"src/amf/nnrf-handler.c","function":"amf_nnrf_handle_nf_discover"},"deprecated":false,"digest":{"function_hash":"82666989101310364076437262106305336036","length":2448},"id":"CVE-2026-90707-d12c7963"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X"}]}