CVE-2025-8698
LOWOpen5GS < 2.7.5 - Reachable Assertion in AMF Service nsmf-handler.c
Title source: llmDescription
A vulnerability was found in Open5GS up to 2.7.5. It has been classified as problematic. Affected is the function amf_nsmf_pdusession_handle_release_sm_context of the file src/amf/nsmf-handler.c of the component AMF Service. The manipulation leads to reachable assertion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The name of the patch is 66bc558e417e70ae216ec155e4e81c14ae0ecf30. It is recommended to apply a patch to fix this issue.
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
technical-description
https://vuldb.com/?id.319128
Permissions Required, VDB Entry signature
permissions-required
https://vuldb.com/?ctiid.319128
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.621282
Exploit, Issue Tracking, Third Party Advisory issue-tracking
https://github.com/open5gs/open5gs/issues/4012
Scores
CVSS v3
3.3
EPSS
0.0018
EPSS Percentile
7.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-617
Status
published
Products (1)
open5gs/open5gs
< 2.7.5
Published
Aug 07, 2025
Tracked Since
Feb 18, 2026