CVE-2026-90707

Source
https://cve.org/CVERecord?id=CVE-2026-90707
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90707.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90707
Published
2026-09-14T10:45:08Z
Modified
2026-09-17T08:02:16Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X CVSS Calculator
Summary
Open5GS Old AMF Discovery Fallback nnrf-handler.c amf_nnrf_try_old_amf_discovery_fallback use after free
Details

A security flaw has been discovered in Open5GS up to 2.7.x. Affected is the function amf_nnrf_try_old_amf_discovery_fallback of the file src/amf/nnrf-handler.c of the component Old AMF Discovery Fallback. The manipulation of the argument discovery_option results in use after free. The attack may be performed from remote. The patch is identified as ddd683a35f8aaac2b7b9884a24cd53bddfc65238. Applying a patch is advised to resolve this issue.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-119",
        "CWE-416"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90707.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "2.5"
                },
                {
                    "last_affected": "2.5"
                },
                {
                    "introduced": "2.6"
                },
                {
                    "last_affected": "2.6"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/open5gs/open5gs

Affected ranges

Type
GIT
Repo
https://github.com/open5gs/open5gs
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.0"
        },
        {
            "last_affected": "2.0"
        },
        {
            "introduced": "2.1"
        },
        {
            "last_affected": "2.1"
        },
        {
            "introduced": "2.2"
        },
        {
            "last_affected": "2.2"
        },
        {
            "introduced": "2.3"
        },
        {
            "last_affected": "2.3"
        },
        {
            "introduced": "2.4"
        },
        {
            "last_affected": "2.4"
        },
        {
            "introduced": "2.7"
        },
        {
            "last_affected": "2.7"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.0
2.1
2.2
2.3
2.4
2.7
v2.*
v2.0.0
v2.0.18
v2.0.22
v2.1.0
v2.1.1
v2.1.3
v2.1.4
v2.1.5
v2.1.7
v2.2.0
v2.2.1
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.2
v2.3.6
v2.4.0
v2.4.1
v2.4.3
v2.4.4
v2.4.5
v2.4.7
v2.4.8
v2.4.9
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.6.6
v2.7.0
v2.7.1
v2.7.2
v2.7.7
v2.8.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90707.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "145325533730271639697057628044301582202",
            "length": 1947
        },
        "id": "CVE-2026-90707-0a548235",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/ddd683a35f8aaac2b7b9884a24cd53bddfc65238",
        "target": {
            "file": "src/amf/nnrf-handler.c",
            "function": "amf_nnrf_handle_failed_amf_discovery"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "81482809240923113474767271872609296911",
                "54649887621598908665781293546502726004",
                "243555174681841255669163456396942241265",
                "262252388139781146943512055351004589490",
                "255588745852037001143230161728789009773",
                "62620928685624160503499001793180048258",
                "17417742761614477236284533499598251525",
                "330315398903319499296713996318655483474",
                "139273765223866279017235078168543792550",
                "284999848277181422916562762239385689754",
                "11514335949590486800677058128240709420",
                "94439711860204125915950974857503625477",
                "190798079971714899547258147245192814452",
                "3156176311557680188467543572093684406",
                "212288291750472162927199326755419730399",
                "318732728975664944474187625382235539740",
                "316308549655715049900646722873140983284",
                "34190236449631450621439303596061165051",
                "188975690839983670783043191328237441673",
                "142875368198450374281672274204628160912",
                "78164890412884877575140924031150555313",
                "85578689364857064332318940093782963527",
                "134054206212726627938836788013098814241",
                "223243837880295071313518321168022997790",
                "148705633158732011269672277409463911272",
                "172218646339745607786836244800839323889",
                "202271290071617596609676312378149818938",
                "101526491535867951163620436879535362903",
                "5194696107461444847842247984448478925",
                "291445330050680751299597861862765629618",
                "188975690839983670783043191328237441673",
                "142875368198450374281672274204628160912"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-90707-b7e8b873",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/ddd683a35f8aaac2b7b9884a24cd53bddfc65238",
        "target": {
            "file": "src/amf/nnrf-handler.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "128162418276963409374489795537792784550",
            "length": 607
        },
        "id": "CVE-2026-90707-c13bd80b",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/ddd683a35f8aaac2b7b9884a24cd53bddfc65238",
        "target": {
            "file": "src/amf/nnrf-handler.c",
            "function": "amf_nnrf_try_old_amf_discovery_fallback"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "82666989101310364076437262106305336036",
            "length": 2448
        },
        "id": "CVE-2026-90707-d12c7963",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/ddd683a35f8aaac2b7b9884a24cd53bddfc65238",
        "target": {
            "file": "src/amf/nnrf-handler.c",
            "function": "amf_nnrf_handle_nf_discover"
        }
    }
]
vanir_signatures_modified
"2026-09-17T08:02:16Z"