Skip to content
Red HatCVE-2026-15720

Red Hat open5gs: out-of-bounds read

High8.6CVE-2026-15720 · Published Jul 14, 2026 · updated Jul 15, 2026

In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.

Red Hat advisory

Affected versions

PackageAffectedFixed in
open5gs
Product
<= 2.7.7No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-125

More Red Hat advisories

All Red Hat
Advisory
A flaw was found in libsoup's WebSocket implementation
High7.5Jul 14
Red Hat libsoup: denial of service
High7.5Jul 14
Red Hat libsoup: denial of service
Medium5.9Jul 14
Red Hat libsoup: out-of-bounds read
Medium6.5Jul 14
Red Hat Enterprise Linux 10: denial of service
Medium5.9Jul 14
Red Hat Enterprise Linux: integer overflow
Medium4.8Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.