CVE-2026-92416

Source
https://cve.org/CVERecord?id=CVE-2026-92416
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92416.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92416
Published
2026-09-16T17:45:09Z
Modified
2026-09-19T08:03:29Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
Open5GS PFCP Session Report Request n4-handler.c smf_n4_handle_session_report_request assertion
Details

A vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function smf_n4_handle_session_report_request of the file src/smf/n4-handler.c of the component PFCP Session Report Request Handler. The manipulation leads to reachable assertion. The attack may be initiated remotely. The identifier of the patch is e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9. It is suggested to install a patch to address this issue.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-617"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92416.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "2.5"
                },
                {
                    "last_affected": "2.5"
                },
                {
                    "introduced": "2.6"
                },
                {
                    "last_affected": "2.6"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/open5gs/open5gs

Affected ranges

Type
GIT
Repo
https://github.com/open5gs/open5gs
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.0"
        },
        {
            "last_affected": "2.0"
        },
        {
            "introduced": "2.1"
        },
        {
            "last_affected": "2.1"
        },
        {
            "introduced": "2.2"
        },
        {
            "last_affected": "2.2"
        },
        {
            "introduced": "2.3"
        },
        {
            "last_affected": "2.3"
        },
        {
            "introduced": "2.4"
        },
        {
            "last_affected": "2.4"
        },
        {
            "introduced": "2.7"
        },
        {
            "last_affected": "2.7"
        },
        {
            "introduced": "2.8.0"
        },
        {
            "last_affected": "2.8.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.0
2.1
2.2
2.3
2.4
2.7
2.8.0
v2.*
v2.0.0
v2.0.18
v2.0.22
v2.1.0
v2.1.1
v2.1.3
v2.1.4
v2.1.5
v2.1.7
v2.2.0
v2.2.1
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.2
v2.3.6
v2.4.0
v2.4.1
v2.4.3
v2.4.4
v2.4.5
v2.4.7
v2.4.8
v2.4.9
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.6.6
v2.7.0
v2.7.1
v2.7.2
v2.7.7
v2.8.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92416.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "297541188228504482982474465994707105197",
                "147047873272428513838731225653964802158",
                "113041754786015590286099239329964745307",
                "213212685139823200782487428611222716368"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-92416-078ff328",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9",
        "target": {
            "file": "src/smf/n4-handler.h"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "271206240628436619296047612964033915252",
                "212314824894937196253898215420702087406",
                "339427954720145360427903823318649049338",
                "133069791804946662144968799658966288223",
                "118292827411724113108205830034462369098",
                "172243175432831167057027214900648308057",
                "31147673050998998330625295360434018011",
                "335698247673092248505387621080299821203",
                "86835081534259162579497768143219396381",
                "190131684572279873738604935371448868480",
                "112329285384018398460926530484538306891",
                "336815521464780055477639644067083723101",
                "238767644525977186838259376181745930132",
                "189128923708447623310304669910346673638",
                "253050250376477056532081587141042453489",
                "32625514586903165239026807471241183251",
                "137558479121858600979009556764051240112",
                "167911606599711640881961399942831103734",
                "134644777793008361301039370436155797447",
                "33756600644301435003469156457824497466",
                "263688820569666536499486579949948043947",
                "116422698649104031567509968266426436009",
                "193076968704716167554267061296437999170",
                "8476709612554721913992023261732905341",
                "167201056470577442555892010216731823954",
                "13800474795302842782766240777617052114",
                "261354783231700769277668233861064185085",
                "100514700376856526053295451592757399309",
                "316776717537481454926352556929320429329",
                "107231517610583190218165051066196157802",
                "335522880731852342677869404654714508075",
                "7602730991902225365422077460003411633",
                "145144886930865198625178693974978337560",
                "212516037449412690841962814621677620141",
                "204699292964296364869422045944212605789",
                "239075800970223049037346329909288968068",
                "154597598131587771460386553181491850690",
                "192565515892541294561133012833116031966",
                "188908885568521226449736250214909970015",
                "296968405650146565131937004538045351667",
                "171673544954751398110854888475571535954",
                "315247095271476425421591153467151975554",
                "102127240882682071129835620526339802130",
                "121966306838359060169920471061192890809",
                "137534953309868738697339753890495274439",
                "124724654405854914091248799913844471639",
                "83082130291903997418942092313570282408",
                "162922471423536893766831312524904869484",
                "287474789705768165880530613650475325709",
                "335522880731852342677869404654714508075",
                "7602730991902225365422077460003411633",
                "203109535119658059367914599138103944823",
                "144500102277192727631601833820017035467",
                "2417612298451542395947426583733388233",
                "201564604991542353147762760382645086037",
                "225289268935396622051054665916222501790",
                "289011863490855541704517811226339781391",
                "161786765988193554508466835036610218323",
                "299660420897536415737019876561277736191",
                "67953195298160809256988524282215866957",
                "214358353091418816338460582317640302899",
                "220563012815570431096845624329512379267",
                "322622472209767794007145904227998910293",
                "234878912581334222017424004588460066263"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-92416-12071ac9",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9",
        "target": {
            "file": "src/smf/n4-handler.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "184499439602850224993372225859904708436",
            "length": 21286
        },
        "id": "CVE-2026-92416-191486e4",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9",
        "target": {
            "file": "src/smf/gsm-sm.c",
            "function": "smf_gsm_state_operational"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "269925444424469268205778129590007223829",
            "length": 7251
        },
        "id": "CVE-2026-92416-ec45380a",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9",
        "target": {
            "file": "src/smf/n4-handler.c",
            "function": "smf_n4_handle_session_report_request"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "82169452715832516073992155969310319959",
                "332859927616562823356330507639862120778",
                "91983132559018819215354337005378978162",
                "113516157356957425710649558409628672853",
                "304401072494834083743172326889032089755",
                "306436226785180383634038504406907530084",
                "200080567105535364713509857388842304920",
                "324486184016324532670547905763997349195",
                "104792047957207900397620365957391950996",
                "72710305030944436711120021327430660709"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-92416-f04c6147",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9",
        "target": {
            "file": "src/smf/gsm-sm.c"
        }
    }
]
vanir_signatures_modified
"2026-09-19T08:03:29Z"