Open5GS MME Buffer Overflow Vulnerability via Malformed ASN.1 Packets on S1AP Interface

Vulnerability

A buffer overflow vulnerability has been identified in Open5GS MME versions through 2.6.4. This issue arises from an improper handling of ASN.1 packets on the S1AP interface, specifically in the processing of 'Handover Required' messages that lack a mandatory 'MME_UE_S1AP_ID' field. The vulnerability can be exploited remotely, leading to a denial-of-service condition by causing the MME to crash. This disruption can persist until the vulnerability is patched.

Impact

Exploitation of this vulnerability causes a stack-based buffer overflow, leading to a crash of the Open5GS MME. This disruption can persist until network operators apply the necessary patch.

Reproduction

To reproduce this vulnerability, send a 'Handover Required' message over the S1AP interface that omits the 'MME_UE_S1AP_ID' field. This can be done by establishing a connection to the MME and transmitting the crafted message, which will trigger the buffer overflow by exploiting the absence of the required identifier.

Remediation

Users can upgrade to Open5GS version 2.7.0 or later, where this vulnerability has been fixed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
9.1
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.