CVE-2026-37229

FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails. A remote unauthenticated attacker can send any non-PER byte sequence (e.g., a single 0x00 byte) over SCTP to the near-RT RIC (port 36421) or iApp (port 36422) to crash the process via SIGABRT. The assertion is reached before any protocol-level validation occurs. All three E2AP protocol versions (v1.01, v2.03, v3.01) are affected.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mosaic5g:flexric:2.0.0:*:*:*:*:*:*:*

History

03 Jun 2026, 17:16

Type Values Removed Values Added
CPE cpe:2.3:a:mosaic5g:flexric:2.0.0:*:*:*:*:*:*:*
References () https://github.com/MinamiKotor1/oran-security-advisories-zhongnan-luo/blob/main/advisories/CVE-2026-37229.md - () https://github.com/MinamiKotor1/oran-security-advisories-zhongnan-luo/blob/main/advisories/CVE-2026-37229.md - Exploit, Mitigation, Third Party Advisory
References () https://gitlab.eurecom.fr/mosaic5g/flexric - () https://gitlab.eurecom.fr/mosaic5g/flexric - Product
First Time Mosaic5g flexric
Mosaic5g

02 Jun 2026, 14:16

Type Values Removed Values Added
CWE CWE-617
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

01 Jun 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 19:16

Updated : 2026-06-03 17:16


NVD link : CVE-2026-37229

Mitre link : CVE-2026-37229

CVE.ORG link : CVE-2026-37229


JSON object : View

Products Affected

mosaic5g

  • flexric
CWE
CWE-617

Reachable Assertion