CVE-2026-2062 | Open5GS up to 2.7.6 PGW S5U Address null pointer dereference (Issue 4257)
A vulnerability marked as problematic has been reported in Open5GS up to 2.7.6. This affects the function sgwc_s5c_handle_modify_bearer_response/sgwc_sxa_handle_session_modification_response of the component PGW S5U Address Handler. The manipulation leads to null pointer dereference.
This vulnerability is documented as CVE-2026-2062. The attack can be initiated remotely. Additionally, an exploit exists.
Applying a patch is the recommended action to fix this issue.