CVE-2026-15194

LOW

Open5GS AMF context.c amf_context_final use after free

Title source: cna
STIX 2.1

Description

A security flaw has been discovered in Open5GS 2.7.7. This affects the function amf_context_final of the file src/amf/context.c of the component AMF. Performing a manipulation results in use after free. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks.

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-377122 | Open5GS AMF context.c amf_context_final use after free
https://vuldb.com/vuln/377122
Signature, Permissions Required signature permissions-required
VDB-377122 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/377122/cti
Third Party Advisory third-party-advisory
CVE-2026-15194 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15194
Third Party Advisory third-party-advisory
Submit #851630 | Open5GS Project Open5GS 2.7.7 Use After Free
https://vuldb.com/submit/851630

Scores

CVSS v3 3.3
EPSS 0.0012
EPSS Percentile 2.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-119 CWE-416
Status published
Products (1)
None/Open5GS 2.7.7
Published Jul 09, 2026
Tracked Since Jul 09, 2026