CVE-2026-15194
LOWOpen5GS AMF context.c amf_context_final use after free
Title source: cnaDescription
A security flaw has been discovered in Open5GS 2.7.7. This affects the function amf_context_final of the file src/amf/context.c of the component AMF. Performing a manipulation results in use after free. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks.
References (6)
Core 6
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-377122 | Open5GS AMF context.c amf_context_final use after free
https://vuldb.com/vuln/377122
Signature, Permissions Required signature
permissions-required
VDB-377122 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/377122/cti
Third Party Advisory third-party-advisory
CVE-2026-15194 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15194
Third Party Advisory third-party-advisory
Submit #851630 | Open5GS Project Open5GS 2.7.7 Use After Free
https://vuldb.com/submit/851630
Product product
https://github.com/open5gs/open5gs/
Scores
CVSS v3
3.3
EPSS
0.0012
EPSS Percentile
2.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-119
CWE-416
Status
published
Products (1)
None/Open5GS
2.7.7
Published
Jul 09, 2026
Tracked Since
Jul 09, 2026