{"id":"CVE-2026-92416","summary":"Open5GS PFCP Session Report Request n4-handler.c smf_n4_handle_session_report_request assertion","details":"A vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function smf_n4_handle_session_report_request of the file src/smf/n4-handler.c of the component PFCP Session Report Request Handler. The manipulation leads to reachable assertion. The attack may be initiated remotely. The identifier of the patch is e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9. It is suggested to install a patch to address this issue.","modified":"2026-09-19T08:03:29.945748Z","published":"2026-09-16T17:45:09.565Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92416.json","unresolved_ranges":[{"extracted_events":[{"introduced":"2.5"},{"last_affected":"2.5"},{"introduced":"2.6"},{"last_affected":"2.6"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"VulDB","cwe_ids":["CWE-617"]},"references":[{"type":"WEB","url":"https://github.com/open5gs/open5gs/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92416.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92416"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-92416"},{"type":"ADVISORY","url":"https://vuldb.com/submit/940464"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/405594"},{"type":"REPORT","url":"https://github.com/open5gs/open5gs/issues/4744"},{"type":"REPORT","url":"https://vuldb.com/vuln/405594/cti"},{"type":"FIX","url":"https://github.com/open5gs/open5gs/commit/e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open5gs/open5gs","events":[{"introduced":"23c57b84b893f585908c95a1d7d94a8e5b484445"},{"fixed":"e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9"}],"database_specific":{"extracted_events":[{"introduced":"2.0"},{"last_affected":"2.0"},{"introduced":"2.1"},{"last_affected":"2.1"},{"introduced":"2.2"},{"last_affected":"2.2"},{"introduced":"2.3"},{"last_affected":"2.3"},{"introduced":"2.4"},{"last_affected":"2.4"},{"introduced":"2.7"},{"last_affected":"2.7"},{"introduced":"2.8.0"},{"last_affected":"2.8.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["2.0","2.1","2.2","2.3","2.4","2.7","2.8.0","v2.8.0","v2.7.7","v2.7.2","v2.7.1","v2.7.0","v2.6.6","v2.6.4","v2.6.3","v2.6.2","v2.6.1","v2.4.9","v2.4.8","v2.4.7","v2.4.5","v2.4.4","v2.4.3","v2.4.1","v2.4.0","v2.3.6","v2.3.2","v2.3.0","v2.2.9","v2.2.8","v2.2.7","v2.2.6","v2.2.1","v2.2.0","v2.1.7","v2.1.5","v2.1.4","v2.1.3","v2.1.1","v2.1.0","v2.0.22","v2.0.18","v2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92416.json","vanir_signatures_modified":"2026-09-19T08:03:29Z","vanir_signatures":[{"id":"CVE-2026-92416-078ff328","signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9","target":{"file":"src/smf/n4-handler.h"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["297541188228504482982474465994707105197","147047873272428513838731225653964802158","113041754786015590286099239329964745307","213212685139823200782487428611222716368"]}},{"id":"CVE-2026-92416-12071ac9","signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9","target":{"file":"src/smf/n4-handler.c"},"deprecated":false,"digest":{"line_hashes":["271206240628436619296047612964033915252","212314824894937196253898215420702087406","339427954720145360427903823318649049338","133069791804946662144968799658966288223","118292827411724113108205830034462369098","172243175432831167057027214900648308057","31147673050998998330625295360434018011","335698247673092248505387621080299821203","86835081534259162579497768143219396381","190131684572279873738604935371448868480","112329285384018398460926530484538306891","336815521464780055477639644067083723101","238767644525977186838259376181745930132","189128923708447623310304669910346673638","253050250376477056532081587141042453489","32625514586903165239026807471241183251","137558479121858600979009556764051240112","167911606599711640881961399942831103734","134644777793008361301039370436155797447","33756600644301435003469156457824497466","263688820569666536499486579949948043947","116422698649104031567509968266426436009","193076968704716167554267061296437999170","8476709612554721913992023261732905341","167201056470577442555892010216731823954","13800474795302842782766240777617052114","261354783231700769277668233861064185085","100514700376856526053295451592757399309","316776717537481454926352556929320429329","107231517610583190218165051066196157802","335522880731852342677869404654714508075","7602730991902225365422077460003411633","145144886930865198625178693974978337560","212516037449412690841962814621677620141","204699292964296364869422045944212605789","239075800970223049037346329909288968068","154597598131587771460386553181491850690","192565515892541294561133012833116031966","188908885568521226449736250214909970015","296968405650146565131937004538045351667","171673544954751398110854888475571535954","315247095271476425421591153467151975554","102127240882682071129835620526339802130","121966306838359060169920471061192890809","137534953309868738697339753890495274439","124724654405854914091248799913844471639","83082130291903997418942092313570282408","162922471423536893766831312524904869484","287474789705768165880530613650475325709","335522880731852342677869404654714508075","7602730991902225365422077460003411633","203109535119658059367914599138103944823","144500102277192727631601833820017035467","2417612298451542395947426583733388233","201564604991542353147762760382645086037","225289268935396622051054665916222501790","289011863490855541704517811226339781391","161786765988193554508466835036610218323","299660420897536415737019876561277736191","67953195298160809256988524282215866957","214358353091418816338460582317640302899","220563012815570431096845624329512379267","322622472209767794007145904227998910293","234878912581334222017424004588460066263"],"threshold":0.9}},{"target":{"file":"src/smf/gsm-sm.c","function":"smf_gsm_state_operational"},"deprecated":false,"digest":{"length":21286,"function_hash":"184499439602850224993372225859904708436"},"id":"CVE-2026-92416-191486e4","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9"},{"digest":{"function_hash":"269925444424469268205778129590007223829","length":7251},"id":"CVE-2026-92416-ec45380a","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9","target":{"file":"src/smf/n4-handler.c","function":"smf_n4_handle_session_report_request"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9","target":{"file":"src/smf/gsm-sm.c"},"deprecated":false,"digest":{"line_hashes":["82169452715832516073992155969310319959","332859927616562823356330507639862120778","91983132559018819215354337005378978162","113516157356957425710649558409628672853","304401072494834083743172326889032089755","306436226785180383634038504406907530084","200080567105535364713509857388842304920","324486184016324532670547905763997349195","104792047957207900397620365957391950996","72710305030944436711120021327430660709"],"threshold":0.9},"id":"CVE-2026-92416-f04c6147"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X"}]}