Denial-of-Service Vulnerability Patched in Open5GS GTP Library
Denial-of-Service Vulnerability Patched in Open5GS GTP Library
09 February 2023
Due to insufficient length validation in the Open5GS GTP library when parsing extension headers in GPRS tunneling protocol (GPTv1-U) messages, a protocol payload with any extension header length set to zero causes an infinite loop.