Vulnerabilidad · Publicado 14/09/2026
Se descubrió un fallo de seguridad (CVE-2026-90707, CVSS 8.3) en Open5GS que afecta la función amf_nnrf_try_old_amf_discovery_fallback, permitiendo ataques remotos de Use After Free mediante manipulación del parámetro discovery_option. Este componente es alta en infraestructuras 5G, poniendo en riesgo operadores de telecomunicaciones y proveedores de servicios móviles en LATAM que dependan de esta solución open source.
A security flaw has been discovered in Open5GS up to 2.7.x. Affected is the function amf_nnrf_try_old_amf_discovery_fallback of the file src/amf/nnrf-handler.c of the component Old AMF Discovery Fallback. The manipulation of the argument discovery_option results in use after free. The attack may be performed from remote. The patch is identified as ddd683a35f8aaac2b7b9884a24cd53bddfc65238. Applying a patch is advised to resolve this issue.
Score: 8.3/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
CWE-119, CWE-416
Publicado en NIST NVD.