A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function hssogsdiamcxmarcb of the file src/hss/hss-cx-path.c of the component VoLTE Cx-Test. The manipulation of the argument OGSKEY_LEN results in stack-based buffer overflow. The attack may be launched remotely. The patch is identified as 54dda041211098730221d0ae20a2f9f9173e7a21. A patch should be applied to remediate this issue.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/15xxx/CVE-2025-15555.json",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "2.7.3"
},
{
"last_affected": "2.7.3"
},
{
"introduced": "2.7.4"
},
{
"last_affected": "2.7.4"
}
]
}
],
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-119",
"CWE-121"
]
}{
"cpe": "cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.7.6"
}
]
}"2026-07-15T19:00:10Z"
[
{
"id": "CVE-2025-15555-34129b1f",
"signature_version": "v1",
"digest": {
"function_hash": "213993595022817816177817134076902112170",
"length": 14336.0
},
"signature_type": "Function",
"target": {
"function": "hss_ogs_diam_cx_mar_cb",
"file": "src/hss/hss-cx-path.c"
},
"source": "https://github.com/open5gs/open5gs/commit/54dda041211098730221d0ae20a2f9f9173e7a21",
"deprecated": false
},
{
"id": "CVE-2025-15555-6374d57c",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"113277272816105327980358157955045789155",
"331843184659930697427739673789453516581",
"188990421608983822363005254150933372594",
"88594859375357997267078913998446231254"
]
},
"signature_type": "Line",
"target": {
"file": "src/hss/hss-cx-path.c"
},
"source": "https://github.com/open5gs/open5gs/commit/54dda041211098730221d0ae20a2f9f9173e7a21",
"deprecated": false
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15555.json"