Red HatCVE-2026-15720
Red Hat open5gs: out-of-bounds read
High8.6CVE-2026-15720 · Published Jul 14, 2026 · updated Jul 15, 2026
In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| open5gs Product | <= 2.7.7 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-125
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 14 | A flaw was found in libsoup's WebSocket implementation | High7.5 | No fix yet |
| Jul 14 | Red Hat libsoup: denial of service | High7.5 | No fix yet |
| Jul 14 | Red Hat libsoup: denial of service | Medium5.9 | No fix yet |
| Jul 14 | Red Hat libsoup: out-of-bounds read | Medium6.5 | No fix yet |
| Jul 14 | Red Hat Enterprise Linux 10: denial of service | Medium5.9 | No fix yet |
| Jul 14 | Red Hat Enterprise Linux: integer overflow | Medium4.8 | No fix yet |