CVE-2026-101035

Source
https://cve.org/CVERecord?id=CVE-2026-101035
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101035.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-101035
Published
2026-09-28T09:30:09Z
Modified
2026-09-30T08:05:22Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
aligungr UERANSIM nr-gnb encode.cpp DecodePlainMmMessage uncaught exception
Details

A flaw has been found in aligungr UERANSIM up to 3.3.0. This affects the function DecodePlainMmMessage in the library src/lib/nas/encode.cpp of the component nr-gnb. Executing a manipulation can lead to uncaught exception. The attack can be launched remotely. The exploit has been published and may be used. This patch is called 1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac. It is best practice to apply a patch to resolve this issue.

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-248"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101035.json"
}
References

Affected packages

Git / github.com/aligungr/ueransim

Affected ranges

Type
GIT
Repo
https://github.com/aligungr/ueransim
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "3.0"
        },
        {
            "last_affected":  "3.0"
        },
        {
            "introduced":  "3.1"
        },
        {
            "last_affected":  "3.1"
        },
        {
            "introduced":  "3.2"
        },
        {
            "last_affected":  "3.2"
        },
        {
            "introduced":  "3.3.0"
        },
        {
            "last_affected":  "3.3.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

3.*
3.0
3.1
3.2
3.3.0
v3.*
v3.0.3
v3.1.0
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.2
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101035.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "286075853778263228491619393065587089941",
                "322046300766709526638858661020801199491",
                "276334377620369167911323654250520971408",
                "311588895950237238698990747246072669974",
                "71784616096216831420278976584102351159",
                "239637462974920773935243136848895413607",
                "10509253954187880465446154027965371027",
                "259578885239905244805530774296148930249",
                "253316907891924684886706141993219215417",
                "163188546403050088395209706780674238496",
                "332590132392539468063629237666963658090",
                "68274130695247172710813095767238118534",
                "20924140791350625196995220535507703555",
                "340159724735568132174603510691597920968",
                "326569205677022795444825068656479262902",
                "40731502701891888054922978095140701958",
                "127090213521947592518591617873235003860",
                "103987219153604485699292649297946212080",
                "119509948550412253948377714320820741464",
                "262419187796150323943948619583114270254",
                "158709907159356512643763470318099984352",
                "307744337934787848828425996815700159939",
                "175579204521627348080167476679871786080",
                "55286806067531430292065137035635301310",
                "108587633537507210242609878158511307392",
                "108587633537507210242609878158511307392",
                "127643384424368775618969202440543419083",
                "319404274502306219729647803353921020665",
                "189428690775578077185957864518026062095",
                "208379263903640845573480479688313824331",
                "168259082826309245723008436909571656437",
                "192574008279990601188692512146150613092",
                "220888302026754445896179838888167683642",
                "24962281845216421740682761664821150534",
                "215596026972130665901239814042149249943",
                "192504236929557680084136701297538937919",
                "111277564383664273900917763549592957167",
                "165455054537842150927516235718568939753",
                "126585742826361496918293058716598920415",
                "236911055419336631575296744084940700114",
                "211303411123439432531047540219238152329",
                "159802113935929849377628377645640474244",
                "206209241378085596091386747350596301406",
                "268576856816905305628389129114767088339",
                "226550012613833793488231484489640117247",
                "39457661293837286167062723288572485065",
                "307835612424698120020468188513369326507",
                "176938207283180712143574237578816450308",
                "70353261465848554655147867588388509464",
                "64054841222904725087379893078015416709",
                "18836072891308340323776159321258954577",
                "260783483135930692921141885237428683214"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-101035-11d301ce",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/aligungr/ueransim/commit/1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac",
        "target":  {
            "file":  "src/gnb/ngap/nas.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "252474432331738246995645898254899121593",
                "94628622377501479327756719281800080798",
                "131032767680577898197033178255987722775",
                "338404499583188457598965476298917170742",
                "290286724505437594040838554644200183080"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-101035-1ed6e9ad",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/aligungr/ueransim/commit/1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac",
        "target":  {
            "file":  "src/gnb/ngap/management.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "23126239650675758114874147686414611838",
            "length":  926
        },
        "id":  "CVE-2026-101035-33e2209f",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/aligungr/ueransim/commit/1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac",
        "target":  {
            "file":  "src/gnb/ngap/nnsf.cpp",
            "function":  "NgapTask::selectAmf"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "178067981201803642495761230188620667981",
            "length":  445
        },
        "id":  "CVE-2026-101035-6da0eff7",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/aligungr/ueransim/commit/1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac",
        "target":  {
            "file":  "src/gnb/ngap/management.cpp",
            "function":  "NgapTask::createUeContext"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "41053802308450729740820279189687535231",
                "295134023023028159792689476183961306463",
                "84415422713871330614938784600576410145",
                "200527059794534464802842256833614887379"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-101035-73d8244a",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/aligungr/ueransim/commit/1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac",
        "target":  {
            "file":  "src/gnb/ngap/nnsf.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "137476789673590735260859608800497681697",
            "length":  2862
        },
        "id":  "CVE-2026-101035-ab57f02c",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/aligungr/ueransim/commit/1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac",
        "target":  {
            "file":  "src/gnb/ngap/nas.cpp",
            "function":  "NgapTask::handleInitialNasTransport"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "74177252639302950768328991698050249621",
                "310260136505282945541100637628992003391",
                "39617953460979940898893159697312464633",
                "108644061375378504972876523714651387108",
                "66711340835329903045288340544530066881",
                "23616795397872989547362104549885106212",
                "139006012578808362052641997083929281393",
                "243559889771958953341390199762391570391",
                "85590387927817054239928452036897688367",
                "204395371345816396082505268389020114066"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-101035-b7717123",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/aligungr/ueransim/commit/1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac",
        "target":  {
            "file":  "src/gnb/ngap/task.hpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "154306598121137354117649090236634436320",
            "length":  902
        },
        "id":  "CVE-2026-101035-c8284c8a",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/aligungr/ueransim/commit/1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac",
        "target":  {
            "file":  "src/gnb/ngap/nas.cpp",
            "function":  "extractSliceInfoAndModifyPdu"
        }
    }
]
vanir_signatures_modified
"2026-09-30T08:05:22Z"