A flaw has been found in aligungr UERANSIM up to 3.3.0. This affects the function DecodePlainMmMessage in the library src/lib/nas/encode.cpp of the component nr-gnb. Executing a manipulation can lead to uncaught exception. The attack can be launched remotely. The exploit has been published and may be used. This patch is called 1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac. It is best practice to apply a patch to resolve this issue.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-248"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101035.json"
}{
"extracted_events": [
{
"introduced": "3.0"
},
{
"last_affected": "3.0"
},
{
"introduced": "3.1"
},
{
"last_affected": "3.1"
},
{
"introduced": "3.2"
},
{
"last_affected": "3.2"
},
{
"introduced": "3.3.0"
},
{
"last_affected": "3.3.0"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101035.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"286075853778263228491619393065587089941",
"322046300766709526638858661020801199491",
"276334377620369167911323654250520971408",
"311588895950237238698990747246072669974",
"71784616096216831420278976584102351159",
"239637462974920773935243136848895413607",
"10509253954187880465446154027965371027",
"259578885239905244805530774296148930249",
"253316907891924684886706141993219215417",
"163188546403050088395209706780674238496",
"332590132392539468063629237666963658090",
"68274130695247172710813095767238118534",
"20924140791350625196995220535507703555",
"340159724735568132174603510691597920968",
"326569205677022795444825068656479262902",
"40731502701891888054922978095140701958",
"127090213521947592518591617873235003860",
"103987219153604485699292649297946212080",
"119509948550412253948377714320820741464",
"262419187796150323943948619583114270254",
"158709907159356512643763470318099984352",
"307744337934787848828425996815700159939",
"175579204521627348080167476679871786080",
"55286806067531430292065137035635301310",
"108587633537507210242609878158511307392",
"108587633537507210242609878158511307392",
"127643384424368775618969202440543419083",
"319404274502306219729647803353921020665",
"189428690775578077185957864518026062095",
"208379263903640845573480479688313824331",
"168259082826309245723008436909571656437",
"192574008279990601188692512146150613092",
"220888302026754445896179838888167683642",
"24962281845216421740682761664821150534",
"215596026972130665901239814042149249943",
"192504236929557680084136701297538937919",
"111277564383664273900917763549592957167",
"165455054537842150927516235718568939753",
"126585742826361496918293058716598920415",
"236911055419336631575296744084940700114",
"211303411123439432531047540219238152329",
"159802113935929849377628377645640474244",
"206209241378085596091386747350596301406",
"268576856816905305628389129114767088339",
"226550012613833793488231484489640117247",
"39457661293837286167062723288572485065",
"307835612424698120020468188513369326507",
"176938207283180712143574237578816450308",
"70353261465848554655147867588388509464",
"64054841222904725087379893078015416709",
"18836072891308340323776159321258954577",
"260783483135930692921141885237428683214"
],
"threshold": 0.9
},
"id": "CVE-2026-101035-11d301ce",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/aligungr/ueransim/commit/1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac",
"target": {
"file": "src/gnb/ngap/nas.cpp"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"252474432331738246995645898254899121593",
"94628622377501479327756719281800080798",
"131032767680577898197033178255987722775",
"338404499583188457598965476298917170742",
"290286724505437594040838554644200183080"
],
"threshold": 0.9
},
"id": "CVE-2026-101035-1ed6e9ad",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/aligungr/ueransim/commit/1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac",
"target": {
"file": "src/gnb/ngap/management.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "23126239650675758114874147686414611838",
"length": 926
},
"id": "CVE-2026-101035-33e2209f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/aligungr/ueransim/commit/1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac",
"target": {
"file": "src/gnb/ngap/nnsf.cpp",
"function": "NgapTask::selectAmf"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "178067981201803642495761230188620667981",
"length": 445
},
"id": "CVE-2026-101035-6da0eff7",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/aligungr/ueransim/commit/1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac",
"target": {
"file": "src/gnb/ngap/management.cpp",
"function": "NgapTask::createUeContext"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"41053802308450729740820279189687535231",
"295134023023028159792689476183961306463",
"84415422713871330614938784600576410145",
"200527059794534464802842256833614887379"
],
"threshold": 0.9
},
"id": "CVE-2026-101035-73d8244a",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/aligungr/ueransim/commit/1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac",
"target": {
"file": "src/gnb/ngap/nnsf.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "137476789673590735260859608800497681697",
"length": 2862
},
"id": "CVE-2026-101035-ab57f02c",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/aligungr/ueransim/commit/1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac",
"target": {
"file": "src/gnb/ngap/nas.cpp",
"function": "NgapTask::handleInitialNasTransport"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"74177252639302950768328991698050249621",
"310260136505282945541100637628992003391",
"39617953460979940898893159697312464633",
"108644061375378504972876523714651387108",
"66711340835329903045288340544530066881",
"23616795397872989547362104549885106212",
"139006012578808362052641997083929281393",
"243559889771958953341390199762391570391",
"85590387927817054239928452036897688367",
"204395371345816396082505268389020114066"
],
"threshold": 0.9
},
"id": "CVE-2026-101035-b7717123",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/aligungr/ueransim/commit/1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac",
"target": {
"file": "src/gnb/ngap/task.hpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "154306598121137354117649090236634436320",
"length": 902
},
"id": "CVE-2026-101035-c8284c8a",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/aligungr/ueransim/commit/1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac",
"target": {
"file": "src/gnb/ngap/nas.cpp",
"function": "extractSliceInfoAndModifyPdu"
}
}
]
"2026-09-30T08:05:22Z"