A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the library lib/pfcp/types.c of the component PFCP Handler. The manipulation results in null pointer dereference. The attack may be launched remotely. The patch is identified as 8f07b507b78ff94776f2cd49276eb116ed93d7f2. A patch should be applied to remediate this issue.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-404",
"CWE-476"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92417.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "2.5"
},
{
"last_affected": "2.5"
},
{
"introduced": "2.6"
},
{
"last_affected": "2.6"
}
],
"source": "AFFECTED_FIELD"
}
]
}{
"extracted_events": [
{
"introduced": "2.0"
},
{
"last_affected": "2.0"
},
{
"introduced": "2.1"
},
{
"last_affected": "2.1"
},
{
"introduced": "2.2"
},
{
"last_affected": "2.2"
},
{
"introduced": "2.3"
},
{
"last_affected": "2.3"
},
{
"introduced": "2.4"
},
{
"last_affected": "2.4"
},
{
"introduced": "2.7"
},
{
"last_affected": "2.7"
},
{
"introduced": "2.8.0"
},
{
"last_affected": "2.8.0"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92417.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"24098572416494072472150174992433296179",
"102011634049678408723019554683134086501",
"334628121676193358138528584516549553354",
"274739736020382121818400731373501563568",
"210255659609178576028994543563152737364",
"337419046187823867919651963679907034869",
"335787937892458187444198325209045812314",
"250497098468205564293817259491093278762",
"51139697771188920290304325508571534461",
"127514162816864497527359258878367565293",
"52802380939896300410953767488256778486",
"191529502536841959918014990497009209665",
"286133117024428088768029061786940989281",
"151404358873934529804179734759712114508",
"285560979195363608657879136400691389807",
"306360920632982004865661843172582088135",
"9183174964650911865162357864238923380",
"91196307377419716945561335865012587841",
"123977867921715620468747127288998793384",
"286572280449947890399812458960675175348",
"147254370855749043554921551782228934106",
"173457517638031104515525655001479029737",
"254786090509838590134396590135160131677",
"47467061996431719772309775666915714413",
"89241205054160065342541941948408079734",
"327965230742814556467182577592754373849",
"158465824985596109661261223363404239674",
"170895426058734597720407471170774687572",
"67331423878907879928133923668761356268",
"144502042865972580787266081535691802737",
"289357496847012309729013772817704057247",
"193451044817949942763423008081306753429",
"8970344623089997919651057272702534298",
"21335361629920037799591448336549689138",
"273336364678120884226003284112256368183",
"163808352132000097005980715737058783445",
"225801961927315224131595807822698099834",
"166795403053640088898616201799400376173",
"23996398597399139794743613190490105800",
"200761104494362634891072566450496824339",
"33910910180840363779350429344562625913",
"171125551633909087742701989347698032986",
"224967580439477737051703460738835686301",
"294728112160571901127606283926061781348",
"300670740419949274378225274731708820411",
"248011634124845179623820673205960667136",
"263549622673136786300606728066195204208",
"323634521850669143210216036796225700585",
"272935410621454145812786262260216656078",
"252651680259454007611679593695565910113",
"210150846499217676718203620049264051794",
"115626134631479398184023481881878018360"
],
"threshold": 0.9
},
"id": "CVE-2026-92417-1c4a47cc",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/8f07b507b78ff94776f2cd49276eb116ed93d7f2",
"target": {
"file": "lib/pfcp/types.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "303523409238699774283300176284088704529",
"length": 3458
},
"id": "CVE-2026-92417-5a7b55cd",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/8f07b507b78ff94776f2cd49276eb116ed93d7f2",
"target": {
"file": "lib/pfcp/types.c",
"function": "ogs_pfcp_parse_sdf_filter"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "160965703418474643946988130580321390516",
"length": 981
},
"id": "CVE-2026-92417-5c301511",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/8f07b507b78ff94776f2cd49276eb116ed93d7f2",
"target": {
"file": "lib/pfcp/types.c",
"function": "ogs_pfcp_parse_dropped_dl_traffic_threshold"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "41450158522692814679943393910763103136",
"length": 1861
},
"id": "CVE-2026-92417-91f4b7f9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/8f07b507b78ff94776f2cd49276eb116ed93d7f2",
"target": {
"file": "lib/pfcp/types.c",
"function": "ogs_pfcp_parse_volume"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "315917536993569287718196560362039213274",
"length": 1932
},
"id": "CVE-2026-92417-a4924139",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/8f07b507b78ff94776f2cd49276eb116ed93d7f2",
"target": {
"file": "lib/pfcp/types.c",
"function": "ogs_pfcp_parse_volume_measurement"
}
}
]
"2026-09-18T08:10:19Z"