CVE-2025-8698

A vulnerability was found in Open5GS up to 2.7.5. It has been classified as problematic. Affected is the function amf_nsmf_pdusession_handle_release_sm_context of the file src/amf/nsmf-handler.c of the component AMF Service. The manipulation leads to reachable assertion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The name of the patch is 66bc558e417e70ae216ec155e4e81c14ae0ecf30. It is recommended to apply a patch to fix this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*

History

29 Apr 2026, 01:00

Type Values Removed Values Added
CPE cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
Summary
  • (es) Se encontró una vulnerabilidad en Open5GS hasta la versión 2.7.5. Se ha clasificado como problemática. La función amf_nsmf_pdusession_handle_release_sm_context del archivo src/amf/nsmf-handler.c del componente AMF Service está afectada. La manipulación genera una aserción accesible. Es necesario realizar un ataque local. Se ha hecho público el exploit y puede que sea utilizado. El parche se llama 66bc558e417e70ae216ec155e4e81c14ae0ecf30. Se recomienda aplicar un parche para solucionar este problema.
First Time Open5gs open5gs
Open5gs
References () https://github.com/open5gs/open5gs/commit/66bc558e417e70ae216ec155e4e81c14ae0ecf30 - () https://github.com/open5gs/open5gs/commit/66bc558e417e70ae216ec155e4e81c14ae0ecf30 - Product
References () https://github.com/open5gs/open5gs/issues/4012 - () https://github.com/open5gs/open5gs/issues/4012 - Exploit, Issue Tracking, Third Party Advisory
References () https://github.com/user-attachments/files/21356631/amf_nsmf_pdusession_handle_release_sm_context.zip - () https://github.com/user-attachments/files/21356631/amf_nsmf_pdusession_handle_release_sm_context.zip - Not Applicable
References () https://vuldb.com/?ctiid.319128 - () https://vuldb.com/?ctiid.319128 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.319128 - () https://vuldb.com/?id.319128 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.621282 - () https://vuldb.com/?submit.621282 - Third Party Advisory, VDB Entry

07 Aug 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-07 21:15

Updated : 2026-04-29 01:00


NVD link : CVE-2025-8698

Mitre link : CVE-2025-8698

CVE.ORG link : CVE-2025-8698


JSON object : View

Products Affected

open5gs

  • open5gs
CWE
CWE-617

Reachable Assertion