CVE-2026-30077

OpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But the crash is consistent for particular inputs. An example input in hex stream is 80 00 00 0E 00 00 01 00 0F 80 02 02 40 00 58 00 01 88.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:openairinterface:openairinterface:2.2.0:*:*:*:*:*:*:*

History

06 Apr 2026, 15:59

Type Values Removed Values Added
CPE cpe:2.3:a:openairinterface:openairinterface:2.2.0:*:*:*:*:*:*:*
First Time Openairinterface
Openairinterface openairinterface
References () https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/issues/76 - () https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/issues/76 - Third Party Advisory, Issue Tracking
References () https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/merge_requests/414 - () https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/merge_requests/414 - Issue Tracking, Mitigation

01 Apr 2026, 14:24

Type Values Removed Values Added
Summary
  • (es) OpenAirInterface V2.2.0 AMF se bloquea cuando no logra decodificar el mensaje. No todas las fallas de decodificación resultan en un bloqueo. Pero el bloqueo es consistente para entradas particulares. Una entrada de ejemplo en flujo hexadecimal es 80 00 00 0E 00 00 01 00 0F 80 02 02 40 00 58 00 01 88.

30 Mar 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-20

30 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 18:16

Updated : 2026-04-06 15:59


NVD link : CVE-2026-30077

Mitre link : CVE-2026-30077

CVE.ORG link : CVE-2026-30077


JSON object : View

Products Affected

openairinterface

  • openairinterface
CWE
CWE-20

Improper Input Validation