CVE-2025-8805

Source
https://cve.org/CVERecord?id=CVE-2025-8805
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8805.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-8805
Published
2025-08-10T11:15:29.913Z
Modified
2026-04-12T22:06:18.919178Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability was determined in Open5GS up to 2.7.5. Affected by this issue is the function smfgsmstatewaitpfcp_deletion of the file src/smf/gsm-sm.c of the component SMF. The manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.7.6 is able to address this issue. The patch is identified as c58b8f081986aaf2a312d73a0a17985518b47fe6. It is recommended to upgrade the affected component.

References

Affected packages

Git / github.com/open5gs/open5gs

Affected ranges

Type
GIT
Repo
https://github.com/open5gs/open5gs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.7.6"
        }
    ]
}

Affected versions

v0.*
v0.1.0
v0.1.1
v0.2.0
v0.3.0
v0.3.1
v0.3.10
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.3.6
v0.3.8
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.5.0
v0.5.1
v0.5.2
v1.*
v1.0.0
v1.1.0
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
v2.*
v2.0.0
v2.0.18
v2.0.22
v2.1.0
v2.1.1
v2.1.3
v2.1.4
v2.1.5
v2.1.7
v2.2.0
v2.2.1
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.2
v2.3.6
v2.4.0
v2.4.1
v2.4.3
v2.4.4
v2.4.5
v2.4.7
v2.4.8
v2.4.9
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.6.6
v2.7.0
v2.7.1
v2.7.2
v2.7.5

Database specific

vanir_signatures_modified
"2026-04-12T22:06:18Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8805.json"
vanir_signatures
[
    {
        "digest": {
            "length": 4924.0,
            "function_hash": "61490306768075923951408687957091975918"
        },
        "target": {
            "file": "src/smf/gsm-sm.c",
            "function": "smf_gsm_state_wait_pfcp_deletion"
        },
        "signature_type": "Function",
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2025-8805-274c48a8",
        "source": "https://github.com/open5gs/open5gs/commit/c58b8f081986aaf2a312d73a0a17985518b47fe6"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "164055518696110674730437876766175874565",
                "54014138822120384516739453409069616512",
                "118227455615250972082490530560828872148",
                "314627021705142519628356306646792490346",
                "93860402162756289283113256886009670854",
                "45501237701576949071660558713849353994",
                "92473834515121775819668126099379501597",
                "161875265931428467315909034129266172293",
                "308781346289152931424574238120758794178",
                "228011867251863204755655916551903191881",
                "202023980723723203016231727669924234736",
                "283361419318785381058239114486052349911",
                "218677510380966350110463379734937592083",
                "273810382587126118284393630098896669414",
                "131679836441677367594759984930504887605",
                "226792163829772817376705610989679818796"
            ]
        },
        "target": {
            "file": "src/smf/gsm-sm.c"
        },
        "signature_type": "Line",
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2025-8805-41292781",
        "source": "https://github.com/open5gs/open5gs/commit/c58b8f081986aaf2a312d73a0a17985518b47fe6"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "176033146007615809543535133770369160847",
                "154395695948315582475524895171734492952",
                "8093209592515321449611416092404184999",
                "75037537951882514569896591061010812879",
                "222623502193228156631530339259009449800",
                "336372230022963784915590487603416404750",
                "208563626295847539758863722211322816284",
                "159281606507344381622592579639513635289",
                "242002022329758434870155720384962273553",
                "265052184391798834503798613080296718218",
                "321460824622827261247781412276176568534",
                "222342926158335346111646814853015329150",
                "54826115759645072753254233614036520145",
                "299200480292781870653288935965606914307",
                "137048598384234741894428530771062091421",
                "138070729265508404667078603140091968374",
                "315315124639441827679895751295921789199",
                "192964880723013761568632860568861013703",
                "137138810487743121519463053163949520019",
                "262767519570101744614786743209946613990",
                "275491451884642338900848187683341482649",
                "262572242459113060642963078552383043066",
                "105464042838079722316023896533223914054",
                "303624371472877287258759829827839979727",
                "229957163288362488848801646054956050674",
                "134217353173577643946976454518555727829",
                "229216331285346465140895906124186823572",
                "162162297543352824473072925927965016295",
                "149262849203398400651604595804211709621",
                "135497251824386848142118675813401365214",
                "291351004919575434261162073385499146469",
                "176033146007615809543535133770369160847",
                "154395695948315582475524895171734492952",
                "8093209592515321449611416092404184999",
                "75037537951882514569896591061010812879",
                "222623502193228156631530339259009449800",
                "336372230022963784915590487603416404750",
                "208563626295847539758863722211322816284",
                "159281606507344381622592579639513635289",
                "242002022329758434870155720384962273553",
                "265052184391798834503798613080296718218",
                "321460824622827261247781412276176568534",
                "222342926158335346111646814853015329150",
                "54826115759645072753254233614036520145",
                "299200480292781870653288935965606914307",
                "137048598384234741894428530771062091421",
                "262767519570101744614786743209946613990",
                "275491451884642338900848187683341482649",
                "262572242459113060642963078552383043066",
                "105464042838079722316023896533223914054",
                "162162297543352824473072925927965016295",
                "149262849203398400651604595804211709621",
                "135497251824386848142118675813401365214",
                "137661583461536997812438256076417352333",
                "111502575674519479537709605278702772764",
                "286554805685848898252469234402798942105",
                "132882563831221217226945322750759931863",
                "321460824622827261247781412276176568534",
                "176033146007615809543535133770369160847",
                "154395695948315582475524895171734492952",
                "8093209592515321449611416092404184999",
                "75037537951882514569896591061010812879",
                "222623502193228156631530339259009449800",
                "336372230022963784915590487603416404750",
                "268724072419813691073575916915917820289",
                "94670051008801437515529286991461893065",
                "317256182541350036425581769393148382049",
                "268473795327714794567645394811408028471",
                "159281606507344381622592579639513635289",
                "242002022329758434870155720384962273553",
                "265052184391798834503798613080296718218",
                "321460824622827261247781412276176568534",
                "176033146007615809543535133770369160847",
                "154395695948315582475524895171734492952",
                "8093209592515321449611416092404184999",
                "75037537951882514569896591061010812879",
                "222623502193228156631530339259009449800",
                "336372230022963784915590487603416404750",
                "268724072419813691073575916915917820289",
                "94670051008801437515529286991461893065",
                "317256182541350036425581769393148382049",
                "268473795327714794567645394811408028471",
                "159281606507344381622592579639513635289",
                "242002022329758434870155720384962273553",
                "265052184391798834503798613080296718218",
                "321460824622827261247781412276176568534",
                "176033146007615809543535133770369160847",
                "154395695948315582475524895171734492952",
                "8093209592515321449611416092404184999",
                "75037537951882514569896591061010812879",
                "222623502193228156631530339259009449800",
                "336372230022963784915590487603416404750",
                "268724072419813691073575916915917820289",
                "94670051008801437515529286991461893065",
                "317256182541350036425581769393148382049",
                "268473795327714794567645394811408028471",
                "159281606507344381622592579639513635289",
                "242002022329758434870155720384962273553",
                "265052184391798834503798613080296718218",
                "321460824622827261247781412276176568534",
                "73219996254065904226386064147856065933",
                "180874907484126318561182909332051324079",
                "329944331570898957731536756586149579427",
                "268473795327714794567645394811408028471",
                "111502575674519479537709605278702772764",
                "286554805685848898252469234402798942105",
                "132882563831221217226945322750759931863",
                "321460824622827261247781412276176568534",
                "162162297543352824473072925927965016295",
                "149262849203398400651604595804211709621",
                "266151928165925044546024744970829682686",
                "275229366080851576716755310690791854719"
            ]
        },
        "target": {
            "file": "src/amf/gmm-sm.c"
        },
        "signature_type": "Line",
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2025-8805-4861e686",
        "source": "https://github.com/open5gs/open5gs/commit/c58b8f081986aaf2a312d73a0a17985518b47fe6"
    },
    {
        "digest": {
            "length": 2554.0,
            "function_hash": "267365274429255400224179414841286395256"
        },
        "target": {
            "file": "src/smf/gsm-sm.c",
            "function": "smf_gsm_state_5gc_session_will_deregister"
        },
        "signature_type": "Function",
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2025-8805-6996132a",
        "source": "https://github.com/open5gs/open5gs/commit/c58b8f081986aaf2a312d73a0a17985518b47fe6"
    }
]