A vulnerability was determined in Open5GS up to 2.7.5. Affected by this issue is the function smfgsmstatewaitpfcp_deletion of the file src/smf/gsm-sm.c of the component SMF. The manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.7.6 is able to address this issue. The patch is identified as c58b8f081986aaf2a312d73a0a17985518b47fe6. It is recommended to upgrade the affected component.
[
{
"target": {
"function": "smf_gsm_state_wait_pfcp_deletion",
"file": "src/smf/gsm-sm.c"
},
"digest": {
"length": 4924.0,
"function_hash": "61490306768075923951408687957091975918"
},
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/c58b8f081986aaf2a312d73a0a17985518b47fe6",
"deprecated": false,
"id": "CVE-2025-8805-274c48a8",
"signature_type": "Function"
},
{
"target": {
"file": "src/smf/gsm-sm.c"
},
"digest": {
"line_hashes": [
"164055518696110674730437876766175874565",
"54014138822120384516739453409069616512",
"118227455615250972082490530560828872148",
"314627021705142519628356306646792490346",
"93860402162756289283113256886009670854",
"45501237701576949071660558713849353994",
"92473834515121775819668126099379501597",
"161875265931428467315909034129266172293",
"308781346289152931424574238120758794178",
"228011867251863204755655916551903191881",
"202023980723723203016231727669924234736",
"283361419318785381058239114486052349911",
"218677510380966350110463379734937592083",
"273810382587126118284393630098896669414",
"131679836441677367594759984930504887605",
"226792163829772817376705610989679818796"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/c58b8f081986aaf2a312d73a0a17985518b47fe6",
"deprecated": false,
"id": "CVE-2025-8805-41292781",
"signature_type": "Line"
},
{
"target": {
"file": "src/amf/gmm-sm.c"
},
"digest": {
"line_hashes": [
"176033146007615809543535133770369160847",
"154395695948315582475524895171734492952",
"8093209592515321449611416092404184999",
"75037537951882514569896591061010812879",
"222623502193228156631530339259009449800",
"336372230022963784915590487603416404750",
"208563626295847539758863722211322816284",
"159281606507344381622592579639513635289",
"242002022329758434870155720384962273553",
"265052184391798834503798613080296718218",
"321460824622827261247781412276176568534",
"222342926158335346111646814853015329150",
"54826115759645072753254233614036520145",
"299200480292781870653288935965606914307",
"137048598384234741894428530771062091421",
"138070729265508404667078603140091968374",
"315315124639441827679895751295921789199",
"192964880723013761568632860568861013703",
"137138810487743121519463053163949520019",
"262767519570101744614786743209946613990",
"275491451884642338900848187683341482649",
"262572242459113060642963078552383043066",
"105464042838079722316023896533223914054",
"303624371472877287258759829827839979727",
"229957163288362488848801646054956050674",
"134217353173577643946976454518555727829",
"229216331285346465140895906124186823572",
"162162297543352824473072925927965016295",
"149262849203398400651604595804211709621",
"135497251824386848142118675813401365214",
"291351004919575434261162073385499146469",
"176033146007615809543535133770369160847",
"154395695948315582475524895171734492952",
"8093209592515321449611416092404184999",
"75037537951882514569896591061010812879",
"222623502193228156631530339259009449800",
"336372230022963784915590487603416404750",
"208563626295847539758863722211322816284",
"159281606507344381622592579639513635289",
"242002022329758434870155720384962273553",
"265052184391798834503798613080296718218",
"321460824622827261247781412276176568534",
"222342926158335346111646814853015329150",
"54826115759645072753254233614036520145",
"299200480292781870653288935965606914307",
"137048598384234741894428530771062091421",
"262767519570101744614786743209946613990",
"275491451884642338900848187683341482649",
"262572242459113060642963078552383043066",
"105464042838079722316023896533223914054",
"162162297543352824473072925927965016295",
"149262849203398400651604595804211709621",
"135497251824386848142118675813401365214",
"137661583461536997812438256076417352333",
"111502575674519479537709605278702772764",
"286554805685848898252469234402798942105",
"132882563831221217226945322750759931863",
"321460824622827261247781412276176568534",
"176033146007615809543535133770369160847",
"154395695948315582475524895171734492952",
"8093209592515321449611416092404184999",
"75037537951882514569896591061010812879",
"222623502193228156631530339259009449800",
"336372230022963784915590487603416404750",
"268724072419813691073575916915917820289",
"94670051008801437515529286991461893065",
"317256182541350036425581769393148382049",
"268473795327714794567645394811408028471",
"159281606507344381622592579639513635289",
"242002022329758434870155720384962273553",
"265052184391798834503798613080296718218",
"321460824622827261247781412276176568534",
"176033146007615809543535133770369160847",
"154395695948315582475524895171734492952",
"8093209592515321449611416092404184999",
"75037537951882514569896591061010812879",
"222623502193228156631530339259009449800",
"336372230022963784915590487603416404750",
"268724072419813691073575916915917820289",
"94670051008801437515529286991461893065",
"317256182541350036425581769393148382049",
"268473795327714794567645394811408028471",
"159281606507344381622592579639513635289",
"242002022329758434870155720384962273553",
"265052184391798834503798613080296718218",
"321460824622827261247781412276176568534",
"176033146007615809543535133770369160847",
"154395695948315582475524895171734492952",
"8093209592515321449611416092404184999",
"75037537951882514569896591061010812879",
"222623502193228156631530339259009449800",
"336372230022963784915590487603416404750",
"268724072419813691073575916915917820289",
"94670051008801437515529286991461893065",
"317256182541350036425581769393148382049",
"268473795327714794567645394811408028471",
"159281606507344381622592579639513635289",
"242002022329758434870155720384962273553",
"265052184391798834503798613080296718218",
"321460824622827261247781412276176568534",
"73219996254065904226386064147856065933",
"180874907484126318561182909332051324079",
"329944331570898957731536756586149579427",
"268473795327714794567645394811408028471",
"111502575674519479537709605278702772764",
"286554805685848898252469234402798942105",
"132882563831221217226945322750759931863",
"321460824622827261247781412276176568534",
"162162297543352824473072925927965016295",
"149262849203398400651604595804211709621",
"266151928165925044546024744970829682686",
"275229366080851576716755310690791854719"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/c58b8f081986aaf2a312d73a0a17985518b47fe6",
"deprecated": false,
"id": "CVE-2025-8805-4861e686",
"signature_type": "Line"
},
{
"target": {
"function": "smf_gsm_state_5gc_session_will_deregister",
"file": "src/smf/gsm-sm.c"
},
"digest": {
"length": 2554.0,
"function_hash": "267365274429255400224179414841286395256"
},
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/c58b8f081986aaf2a312d73a0a17985518b47fe6",
"deprecated": false,
"id": "CVE-2025-8805-6996132a",
"signature_type": "Function"
}
]