OpenAirInterface CN5G AMF Improper File Descriptor Handling in Closed Connections Allowing Denial-of-Service

Vulnerability

A denial-of-service vulnerability has been identified in OpenAirInterface CN5G AMF versions through 2.0.0. The issue arises from improper handling of file descriptors for closed SCTP connections, specifically on the N2 interface. This flaw allows attackers to exhaust server resources by repeatedly opening and closing connections, leading to resource exhaustion and potential service disruption.

Impact

Exploitation of this vulnerability causes resource exhaustion on the server, leading to a denial-of-service condition where the server becomes overwhelmed and unable to handle legitimate connections or requests.

Reproduction

The vulnerability can be reproduced by establishing more than 1024 SCTP connections to the server's N2 interface, which can be done by an unauthenticated mobile device or over the internet using Wi-Fi calling. Once the connection limit is exceeded, the server will crash.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
8.0
remediation
0.0
relevance
0.0
threat
4.8
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.