No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 24 Aug 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in Open5GS 2.8.0. Affected by this issue is the function hss_ogs_diam_s6a_air_cb of the file src/hss/hss-s6a-path.c of the component S6a Authentication-Information-Request Handler. Such manipulation of the argument Visited-PLMN-Id leads to heap-based buffer overflow. The attack may be performed from remote. The name of the patch is a9c82ee0b590d76a581b0580cb46b598984e2392. A patch should be applied to remediate this issue. | |
| Title | Open5GS S6a Authentication-Information-Request hss-s6a-path.c hss_ogs_diam_s6a_air_cb heap-based overflow | |
| First Time appeared |
Open5gs
Open5gs open5gs |
|
| Weaknesses | CWE-119 CWE-122 |
|
| CPEs | cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Open5gs
Open5gs open5gs |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-23T23:45:09.676Z
Reserved: 2026-08-23T11:34:31.832Z
Link: CVE-2026-78156
No data.
Status : Deferred
Published: 2026-08-24T00:16:47.367
Modified: 2026-08-24T16:40:53.647
Link: CVE-2026-78156
No data.
OpenCVE Enrichment
Updated: 2026-08-24T01:30:04Z