A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function hssogsdiamcxmarcb of the file src/hss/hss-cx-path.c of the component VoLTE Cx-Test. The manipulation of the argument OGSKEY_LEN results in stack-based buffer overflow. The attack may be launched remotely. The patch is identified as 54dda041211098730221d0ae20a2f9f9173e7a21. A patch should be applied to remediate this issue.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15555.json"
[
{
"source": "https://github.com/open5gs/open5gs/commit/54dda041211098730221d0ae20a2f9f9173e7a21",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-15555-34129b1f",
"digest": {
"length": 14336.0,
"function_hash": "213993595022817816177817134076902112170"
},
"signature_type": "Function",
"target": {
"file": "src/hss/hss-cx-path.c",
"function": "hss_ogs_diam_cx_mar_cb"
}
},
{
"source": "https://github.com/open5gs/open5gs/commit/54dda041211098730221d0ae20a2f9f9173e7a21",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-15555-6374d57c",
"digest": {
"threshold": 0.9,
"line_hashes": [
"113277272816105327980358157955045789155",
"331843184659930697427739673789453516581",
"188990421608983822363005254150933372594",
"88594859375357997267078913998446231254"
]
},
"signature_type": "Line",
"target": {
"file": "src/hss/hss-cx-path.c"
}
}
]