A vulnerability was found in Open5GS up to 2.7.1. This affects the function hssogsdiams6aaircb/hssogsdiams6aulrcb of the file src/hss/hss-s6a-path.c of the component Diameter S6a Interface. Performing a manipulation of the argument os.len results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 2.7.2 is able to mitigate this issue. The patch is named e89aa79efe629ae90f59dcdf8847c117d9a7da86. It is suggested to upgrade the affected component.
{
"cwe_ids": [
"CWE-119",
"CWE-121"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/14xxx/CVE-2024-14042.json",
"cna_assigner": "VulDB"
}"2026-08-14T09:05:42Z"
[
{
"id": "CVE-2024-14042-021355dc",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 3536.0,
"function_hash": "64878939110562238249368093260391795971"
},
"source": "https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76",
"target": {
"function": "nrf_nnrf_handle_nf_status_update",
"file": "src/nrf/nnrf-handler.c"
}
},
{
"id": "CVE-2024-14042-1fe2c584",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 5934.0,
"function_hash": "137852393407895265767706288030418867306"
},
"source": "https://github.com/open5gs/open5gs/commit/e89aa79efe629ae90f59dcdf8847c117d9a7da86",
"target": {
"function": "hss_ogs_diam_s6a_ulr_cb",
"file": "src/hss/hss-s6a-path.c"
}
},
{
"id": "CVE-2024-14042-20392e9b",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 4813.0,
"function_hash": "54820529185091344345021353014457357810"
},
"source": "https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76",
"target": {
"function": "nrf_nnrf_handle_nf_status_subscribe",
"file": "src/nrf/nnrf-handler.c"
}
},
{
"id": "CVE-2024-14042-2655f6fa",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"165690721616426534099534328523936116807",
"261243168294521985828275779675784209436",
"58800936853138522851815033994950632698",
"292292056152113626468784833482101536932",
"165690721616426534099534328523936116807",
"104451065855420431323085799889312635048",
"273600911875957829853736629726786116237",
"232808879163079335822956491958052534515"
]
},
"source": "https://github.com/open5gs/open5gs/commit/e89aa79efe629ae90f59dcdf8847c117d9a7da86",
"target": {
"file": "src/hss/hss-s6a-path.c"
}
},
{
"id": "CVE-2024-14042-281cabac",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"125930618343269423166171477047759652882",
"215167919317852745312758765163516360590",
"302795111643205430510295325505330434463",
"181476369417000736944089116307162828356",
"235767993398620799680443723605133230991",
"172267876852941121271025232930121274010"
]
},
"source": "https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76",
"target": {
"file": "lib/sbi/nnrf-handler.c"
}
},
{
"id": "CVE-2024-14042-325188eb",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 1587.0,
"function_hash": "96134067957720978197926552255752399026"
},
"source": "https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76",
"target": {
"function": "handle_validity_time",
"file": "lib/sbi/nnrf-handler.c"
}
},
{
"id": "CVE-2024-14042-78f3ead2",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 5999.0,
"function_hash": "195088638377963736100241869331406785003"
},
"source": "https://github.com/open5gs/open5gs/commit/e89aa79efe629ae90f59dcdf8847c117d9a7da86",
"target": {
"function": "hss_ogs_diam_s6a_air_cb",
"file": "src/hss/hss-s6a-path.c"
}
},
{
"id": "CVE-2024-14042-dd1116af",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"257395929218348314448842538364456807789",
"128245168593575346110932044743833054792",
"227731254385837120802644455867923325373",
"229481775018251413784647459407184981825",
"161079306334917913917812145518152183846",
"292392589117498619929147263163282864055",
"276187307341130075856667759820190175219",
"158080439368666746858121958480347926241",
"172267164008105062097219190928411450221",
"289039494816874545190321298637836742144",
"13270842352182382920178975182495404891",
"140733506554091670395272410318360076360",
"88958982143766265032471606082736208427"
]
},
"source": "https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76",
"target": {
"file": "src/nrf/nnrf-handler.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-14042.json"