CVE-2026-82590

Source
https://cve.org/CVERecord?id=CVE-2026-82590
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82590.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82590
Published
2026-08-30T22:30:11.286Z
Modified
2026-09-02T08:08:59.500369Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
Open5GS SMF nudm-handler.c smf_nudm_sdm_handle_get assertion
Details

A weakness has been identified in Open5GS up to 2.7.7. The affected element is the function smfnudmsdmhandleget of the file src/smf/nudm-handler.c of the component SMF. Executing a manipulation of the argument preemptCap can lead to reachable assertion. The attack may be launched remotely. Upgrading to version 2.8.0 is sufficient to fix this issue. This patch is called 4554405f29bffd7562abedbee63484825bd90cd5. You should upgrade the affected component.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82590.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "2.7.3"
                },
                {
                    "last_affected": "2.7.3"
                },
                {
                    "introduced": "2.7.4"
                },
                {
                    "last_affected": "2.7.4"
                }
            ]
        }
    ],
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-617"
    ]
}
References

Affected packages

Git / github.com/open5gs/open5gs

Affected ranges

Type
GIT
Repo
https://github.com/open5gs/open5gs
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "2.7.0"
        },
        {
            "last_affected": "2.7.0"
        },
        {
            "introduced": "2.7.1"
        },
        {
            "last_affected": "2.7.1"
        },
        {
            "introduced": "2.7.2"
        },
        {
            "last_affected": "2.7.2"
        },
        {
            "introduced": "2.7.5"
        },
        {
            "last_affected": "2.7.5"
        },
        {
            "introduced": "2.7.6"
        },
        {
            "last_affected": "2.7.6"
        },
        {
            "introduced": "2.7.7"
        },
        {
            "last_affected": "2.7.7"
        }
    ]
}

Affected versions

2.*
2.7.0
2.7.1
2.7.2
2.7.5
2.7.6
2.7.7
v2.*
v2.7.0
v2.7.1
v2.7.2
v2.7.7

Database specific

vanir_signatures
[
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1584.0,
            "function_hash": "269989511999798805408776959487049030916"
        },
        "id": "CVE-2026-82590-3271f6be",
        "target": {
            "function": "test_db_insert_ue",
            "file": "tests/common/context.c"
        },
        "source": "https://github.com/open5gs/open5gs/commit/157f611a530e292e40ec50f9d23f0ef5d4fcd6a6",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "89714231803210300349029899902762723787",
                "216254685653352833187689837665217332085",
                "335816294610166792862992334015549679232",
                "45647755495410842334388829683427303171",
                "300040392950149666439873900614186251387",
                "44008193511893640358241655468743290907",
                "101891682352354475027959434028209490796",
                "45647755495410842334388829683427303171"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-82590-79321a86",
        "target": {
            "file": "tests/common/context.c"
        },
        "source": "https://github.com/open5gs/open5gs/commit/157f611a530e292e40ec50f9d23f0ef5d4fcd6a6",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 8411.0,
            "function_hash": "282754978359090755822550112781554459360"
        },
        "id": "CVE-2026-82590-8e761944",
        "target": {
            "function": "smf_nudm_sdm_handle_get",
            "file": "src/smf/nudm-handler.c"
        },
        "source": "https://github.com/open5gs/open5gs/commit/4554405f29bffd7562abedbee63484825bd90cd5",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "13670954421577463282614854307106837692",
                "68386743934614122915530000309943372734",
                "307435294826656885429427070035608026412",
                "196724408439031209333121585314913160518",
                "238151264661756252838181343266542701287",
                "257955280968717005666993956276319597920",
                "34632011833808292748505163552896450610",
                "323834225720042893694891229507994962416",
                "329397806509085839600555821919025445106",
                "221185434686963644885723888729975125367",
                "266961930735723933530033539141030355935",
                "62850239752200469972557854292232540433",
                "139001994912972410097790460848156968487",
                "321803297248836393343563794053497796727",
                "28049310975317151493508402846460745839",
                "5665490572233985671483204700697399694",
                "332007451518294697027142834870726877305",
                "270215871633638087889196050272141192628",
                "65221202539183675254572260247373955930",
                "63202674869640520871887538172651143368"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-82590-d087aca3",
        "target": {
            "file": "src/smf/nudm-handler.c"
        },
        "source": "https://github.com/open5gs/open5gs/commit/4554405f29bffd7562abedbee63484825bd90cd5",
        "signature_version": "v1"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82590.json"
vanir_signatures_modified
"2026-09-02T08:08:59Z"