CVE-2026-90707
A security flaw has been discovered in Open5GS up to 2.7.x. Affected is the function amf_nnrf_try_old_amf_discovery_fallback of the file src/amf/nnrf-handler.c of the component Old AMF Discovery Fallback. The manipulation of the argument discovery_option results in use after free. The attack may be performed from remote. The patch is identified as ddd683a35f8aaac2b7b9884a24cd53bddfc65238. Applying a patch is advised to resolve this issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 8.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X
- EPSS probability
- 0.31%
- CWE
- CWE-416, CWE-119
- Published
- 2026-09-14
- Last modified
- 2026-09-15
Affected products
- n/a Open5GS
- n/a Open5GS
- n/a Open5GS
- n/a Open5GS
- n/a Open5GS
- n/a Open5GS
- n/a Open5GS
- n/a Open5GS
Weakness type
Related vulnerabilities
- CVE-2026-87464 — Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outs
- CVE-2026-87646 — Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitr
- CVE-2026-87637 — Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbi
- CVE-2026-87634 — Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute
- CVE-2026-87609 — Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitra
- CVE-2026-87607 — Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially exec
- CVE-2026-87581 — Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineeri
- CVE-2026-87558 — Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitr