A vulnerability was identified in Open5GS up to 2.7.1. This issue affects the function pcrfrxaarcb of the file src/pcrf/pcrf-rx-path.c of the component Diameter Rx Handler. The manipulation of the argument numofmediacomponent/numofsub leads to buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. Upgrading to version 2.7.2 is capable of addressing this issue. The identifier of the patch is 87b4e4535c77ded627cdb6f4e4e2e3ea761f40b7. It is recommended to upgrade the affected component.
{
"cwe_ids": [
"CWE-119",
"CWE-120"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/14xxx/CVE-2024-14044.json",
"cna_assigner": "VulDB"
}"2026-08-14T09:05:43Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-14044.json"
[
{
"deprecated": false,
"target": {
"file": "src/nrf/nnrf-handler.c",
"function": "nrf_nnrf_handle_nf_status_update"
},
"id": "CVE-2024-14044-021355dc",
"signature_version": "v1",
"digest": {
"function_hash": "64878939110562238249368093260391795971",
"length": 3536.0
},
"source": "https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76",
"signature_type": "Function"
},
{
"deprecated": false,
"target": {
"file": "src/pcrf/pcrf-rx-path.c",
"function": "pcrf_rx_aar_cb"
},
"id": "CVE-2024-14044-07b57908",
"signature_version": "v1",
"digest": {
"function_hash": "147604136178718490444537972582417308816",
"length": 8016.0
},
"source": "https://github.com/open5gs/open5gs/commit/87b4e4535c77ded627cdb6f4e4e2e3ea761f40b7",
"signature_type": "Function"
},
{
"deprecated": false,
"target": {
"file": "src/nrf/nnrf-handler.c",
"function": "nrf_nnrf_handle_nf_status_subscribe"
},
"id": "CVE-2024-14044-20392e9b",
"signature_version": "v1",
"digest": {
"function_hash": "54820529185091344345021353014457357810",
"length": 4813.0
},
"source": "https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76",
"signature_type": "Function"
},
{
"deprecated": false,
"target": {
"file": "src/pcf/npcf-handler.c",
"function": "pcf_npcf_policyauthorization_handle_update"
},
"id": "CVE-2024-14044-25049993",
"signature_version": "v1",
"digest": {
"function_hash": "18192948449117180226908169912032378018",
"length": 8312.0
},
"source": "https://github.com/open5gs/open5gs/commit/87b4e4535c77ded627cdb6f4e4e2e3ea761f40b7",
"signature_type": "Function"
},
{
"deprecated": false,
"target": {
"file": "lib/sbi/nnrf-handler.c"
},
"id": "CVE-2024-14044-281cabac",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"125930618343269423166171477047759652882",
"215167919317852745312758765163516360590",
"302795111643205430510295325505330434463",
"181476369417000736944089116307162828356",
"235767993398620799680443723605133230991",
"172267876852941121271025232930121274010"
]
},
"source": "https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76",
"signature_type": "Line"
},
{
"deprecated": false,
"target": {
"file": "lib/sbi/nnrf-handler.c",
"function": "handle_validity_time"
},
"id": "CVE-2024-14044-325188eb",
"signature_version": "v1",
"digest": {
"function_hash": "96134067957720978197926552255752399026",
"length": 1587.0
},
"source": "https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76",
"signature_type": "Function"
},
{
"deprecated": false,
"target": {
"file": "src/pcf/npcf-handler.c",
"function": "pcf_npcf_policyauthorization_handle_create"
},
"id": "CVE-2024-14044-6b5ffb2b",
"signature_version": "v1",
"digest": {
"function_hash": "13212232465897786294742541015130279189",
"length": 10497.0
},
"source": "https://github.com/open5gs/open5gs/commit/87b4e4535c77ded627cdb6f4e4e2e3ea761f40b7",
"signature_type": "Function"
},
{
"deprecated": false,
"target": {
"file": "src/pcf/npcf-handler.c"
},
"id": "CVE-2024-14044-8cf062f5",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"204793006264660394367981042727438485316",
"311101534145372889206998138529986822772",
"169088331052639315700976612082013649431",
"100154423288074907537506363435926965371",
"193904695077764666821392215825402966788",
"161000577824216624348762733969298082738",
"45878280845450755909323669902372540311",
"140779327977521274742867145399604691902",
"184661140544202308497491813553030367954",
"134406121662650797176228911483048292309",
"320054545811097338444923951181831459634",
"133575607881647984770037695189742256630",
"129213306190485830353552047798325018295",
"204793006264660394367981042727438485316",
"311101534145372889206998138529986822772",
"169088331052639315700976612082013649431",
"100154423288074907537506363435926965371",
"193904695077764666821392215825402966788",
"161000577824216624348762733969298082738",
"45878280845450755909323669902372540311",
"140779327977521274742867145399604691902",
"184661140544202308497491813553030367954",
"134406121662650797176228911483048292309",
"320054545811097338444923951181831459634",
"133575607881647984770037695189742256630",
"129213306190485830353552047798325018295"
]
},
"source": "https://github.com/open5gs/open5gs/commit/87b4e4535c77ded627cdb6f4e4e2e3ea761f40b7",
"signature_type": "Line"
},
{
"deprecated": false,
"target": {
"file": "src/pcrf/pcrf-rx-path.c"
},
"id": "CVE-2024-14044-bf3900ad",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"254453987138905757351857502198900335820",
"114733116424570344929990833007916507036",
"158761396504993995495315816566169220376",
"315510422964043923672904289870634856093",
"181140169317762666470096375185128915493",
"135487889361693909411668110705735661852",
"226029754925402675508241773604952460455",
"54975882959056192265739782291394804833",
"174086853351604158555286148280632180752",
"245880674244821404709820985039620987055",
"160179689336284063535888151986969254974",
"32123406595770501607321507717995003868",
"322079887909876875896333613338611245930"
]
},
"source": "https://github.com/open5gs/open5gs/commit/87b4e4535c77ded627cdb6f4e4e2e3ea761f40b7",
"signature_type": "Line"
},
{
"deprecated": false,
"target": {
"file": "src/nrf/nnrf-handler.c"
},
"id": "CVE-2024-14044-dd1116af",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"257395929218348314448842538364456807789",
"128245168593575346110932044743833054792",
"227731254385837120802644455867923325373",
"229481775018251413784647459407184981825",
"161079306334917913917812145518152183846",
"292392589117498619929147263163282864055",
"276187307341130075856667759820190175219",
"158080439368666746858121958480347926241",
"172267164008105062097219190928411450221",
"289039494816874545190321298637836742144",
"13270842352182382920178975182495404891",
"140733506554091670395272410318360076360",
"88958982143766265032471606082736208427"
]
},
"source": "https://github.com/open5gs/open5gs/commit/43fa4857cce8af6b6ec3c8e3b0cbf99444948f76",
"signature_type": "Line"
}
]