{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-29T17:04:38.192","vulnerabilities":[{"cve":{"id":"CVE-2022-39063","sourceIdentifier":"disclosure@synopsys.com","published":"2022-09-16T19:15:10.030","lastModified":"2026-06-17T04:57:31.653","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"When Open5GS UPF receives a PFCP Session Establishment Request, it stores related values for building the PFCP Session Establishment Response. Once UPF receives a request, it gets the f_teid_len from incoming message, and then uses it to copy data from incoming message to struct f_teid without checking the maximum length. If the pdi.local_f_teid.len exceeds the maximum length of the struct of f_teid, the memcpy() overwrites the fields (e.g., f_teid_len) after f_teid in the pdr struct. After parsing the request, the UPF starts to build a response. The f_teid_len with its overwritten value is used as a length for memcpy(). A segmentation fault occurs, as a result of a memcpy(), if this overwritten value is large enough."},{"lang":"es","value":"Cuando Open5GS UPF recibe una petición de establecimiento de sesión PFCP, almacena los valores relacionados para construir la respuesta de establecimiento de sesión PFCP. Una vez que UPF recibe una petición, obtiene el f_teid_len del mensaje entrante, y luego lo usa para copiar los datos del mensaje entrante a la estructura f_teid sin comprobar la longitud máxima. Si pdi.local_f_teid.len supera la longitud máxima de la struct de f_teid, memcpy() sobrescribe los campos (por ejemplo, f_teid_len) después de f_teid en la struct de pdr. Después de analizar la petición, la UPF comienza a construir una respuesta. El f_teid_len con su valor sobrescrito es usado como longitud para memcpy(). Es producido un fallo de segmentación, como resultado de una memcpy(), si este valor sobrescrito es lo suficientemente grande"}],"affected":[{"source":"disclosure@synopsys.com","affectedData":[{"vendor":"Open5GS","product":"Open5GS","versions":[{"version":"<2.4.9","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@synopsys.com","type":"Secondary","description":[{"lang":"en","value":"CWE-676"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*","versionEndIncluding":"2.4.9","matchCriteriaId":"A9B26E94-388C-44FD-ABE2-E2DFBF3BD1C3"}]}]}],"references":[{"url":"https://www.synopsys.com/blogs/software-security/cyrc-advisory-open5gs/","source":"disclosure@synopsys.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.synopsys.com/blogs/software-security/cyrc-advisory-open5gs/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}}]}