High severity7.5NVD Advisory· Published Apr 8, 2026· Updated Apr 14, 2026
CVE-2026-30075
CVE-2026-30075
Description
OpenAirInterface Version 2.2.0 has a Buffer Overflow vulnerability in processing UplinkNASTransport containing Authentication Response containing a NAS PDU with oversize response (For example 100 byte). The response is decoded by AMF and passed to the AUSF component for verification. AUSF crashes on receiving this oversize response. This can prohibit users from further registration and verification and can cause Denial of Services (DoS).
Affected products
1- cpe:2.3:a:openairinterface:oai-cn5g-amf:2.2.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- gitlab.eurecom.fr/oai/cn5g/oai-cn5g-ausf/-/issues/6nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.