OpenAirInterface CN5G AMF Stack Overflow Vulnerability in SCTP Receiver Thread Component Allowing Denial-of-Service

Vulnerability

A stack overflow vulnerability has been identified in the 'sctp_server::sctp_receiver_thread' component of OpenAirInterface CN5G AMF, in versions through 2.0.0. This vulnerability allows attackers to cause a denial-of-service (DoS) by repeatedly establishing SCTP connections with the N2 interface. The issue arises from missing bounds checks on file descriptors, which can lead to a buffer overflow when more than 1024 descriptors are open.

Impact

Exploitation of this vulnerability causes a stack-based buffer overflow, which can lead to memory corruption and potentially allow for arbitrary code execution.

Reproduction

The vulnerability can be reproduced by establishing more than 1024 SCTP connections to the server's N2 interface. This can be done by automating the process of opening connections, such as with a script or tool that supports SCTP, and maintaining the connections until the server crashes.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
8.8
remediation
0.0
relevance
0.0
threat
4.8
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.