A vulnerability has been found in Open5GS up to 2.7.6. Affected is the function ogs_pfcp_pdr_find_or_add/ogs_pfcp_far_find_or_add/ogs_pfcp_urr_find_or_add/ogs_pfcp_qer_find_or_add in the library lib/pfcp/context.c of the component QER/FAR/URR/PDR. The manipulation leads to reachable assertion. It is possible to initiate the attack remotely. The attack's complexity is rated as high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 442369dcd964f03d95429a6a01a57ed21f7779b7. Applying a patch is the recommended action to fix this issue.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-617"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14954.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "2.7.3"
},
{
"last_affected": "2.7.3"
},
{
"introduced": "2.7.4"
},
{
"last_affected": "2.7.4"
}
],
"source": "AFFECTED_FIELD"
}
]
}{
"cpe": "cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.7.5"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14954.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "99348471419656350091764651416494565248",
"length": 228
},
"id": "CVE-2025-14954-0d94d1a8",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/442369dcd964f03d95429a6a01a57ed21f7779b7",
"target": {
"file": "lib/pfcp/context.c",
"function": "ogs_pfcp_qer_find_or_add"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "99348471419656350091764651416494565248",
"length": 228
},
"id": "CVE-2025-14954-6e0daa23",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/442369dcd964f03d95429a6a01a57ed21f7779b7",
"target": {
"file": "lib/pfcp/context.c",
"function": "ogs_pfcp_far_find_or_add"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"259291970197500026470746520357610721392",
"199803091516292476448809222493988811577",
"180919232541597776046043774683057551274",
"50608585057955660921075431575047991704",
"22162246116183490659297086474082581199",
"124170030514722321650064277416894424365",
"161905256525036226125030588924592710666",
"320711779656746574363603578940672477820",
"175510109846134957050118006066892913804",
"295890135931699163757092747498147702111",
"147817652438727747242877400472634449408",
"215263551927558648941200361127825145441",
"104323061410415695165795615922597443232",
"57535600661599625295060740718253124114",
"75206800299705008042034449471198714119",
"108229233634851663498039418044864081663",
"155392759454241145145501003020503724688",
"36173400567354104693661768995958481755",
"83044167115267024851882569984385182339",
"109350331485914057810279805197144444560"
],
"threshold": 0.9
},
"id": "CVE-2025-14954-773e5de4",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/442369dcd964f03d95429a6a01a57ed21f7779b7",
"target": {
"file": "lib/pfcp/handler.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "99348471419656350091764651416494565248",
"length": 228
},
"id": "CVE-2025-14954-b7df4878",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/442369dcd964f03d95429a6a01a57ed21f7779b7",
"target": {
"file": "lib/pfcp/context.c",
"function": "ogs_pfcp_urr_find_or_add"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "99348471419656350091764651416494565248",
"length": 228
},
"id": "CVE-2025-14954-cf502cdc",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/442369dcd964f03d95429a6a01a57ed21f7779b7",
"target": {
"file": "lib/pfcp/context.c",
"function": "ogs_pfcp_pdr_find_or_add"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"154627695195074138166761654794205512236",
"131595413227037896249763006367947051227",
"239341864626613627402317494672046569521",
"316734446460986720202540776140184306673",
"255499268516263147423863421951903081755",
"204590800458089228134615068561881504675",
"58633263965455771706196646282962598001",
"104554318124809263498406124537925946471",
"254484800990544152760403425184859783926",
"152179835952243477602576433006379010912",
"30902956542134162793631392988359078171",
"133356252044353006657796594645328805196",
"295259385680568296896230624412647065009",
"49421976990443233639569547460018554539",
"294037414799643470258222285797691779996",
"210423505155969253819024677925826313789"
],
"threshold": 0.9
},
"id": "CVE-2025-14954-ed048a32",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/442369dcd964f03d95429a6a01a57ed21f7779b7",
"target": {
"file": "lib/pfcp/context.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "226016123465411250321008823215246105336",
"length": 8388
},
"id": "CVE-2025-14954-f669db2f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/442369dcd964f03d95429a6a01a57ed21f7779b7",
"target": {
"file": "lib/pfcp/handler.c",
"function": "ogs_pfcp_handle_create_pdr"
}
}
]
"2026-08-12T15:13:39Z"