Sceawere
Vulnerability Detail
CVE-2026-100892UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
UERANSIM Memory Corruption Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 7h ago
- Vendor
- aligungr
- Product
- UERANSIM
- Attack Type
- Memory Corruption
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was found in aligungr UERANSIM up to 3.3.0. This affects the function ULInformationTransfer of the file src/gnb/rrc/handler.cpp of the component nr-gnb. Performing a manipulation of the argument dedicatedNASMessage results in memory corruption. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-09-28T01:16:28.583Z",
"pubdate": "2026-09-28T01:16:28.583Z",
"executiveSummary": "A critical memory corruption vulnerability has been identified in the nr-gnb component of UERANSIM versions up to 3.3.0. The vulnerability resides in the ULInformationTransfer function within src/gnb/rrc/handler.cpp, where improper handling of the dedicatedNASMessage argument leads to memory corruption.\nThis vulnerability is remotely exploitable, allowing an unauthenticated remote attacker to trigger the flaw without requiring prior system access. Successful exploitation can lead to arbitrary memory corruption, potentially resulting in a denial-of-service state or remote code execution, depending on the memory layout and specific exploitation techniques applied.\nGiven that the exploit code has been made publicly available and the vendor has remained unresponsive to disclosure efforts, the risk profile is elevated. Organizations deploying UERANSIM should treat this as a high-priority security issue, as the component is directly exposed to network-based inputs in simulated 5G environments.",
"technicalDetails": "The vulnerability is located in the Radio Resource Control (RRC) layer of the gNB simulation, specifically within the ULInformationTransfer message handling logic. The root cause stems from insufficient bounds checking and input validation performed on the dedicatedNASMessage field when processing incoming RRC messages.\nWhen a specially crafted ULInformationTransfer message is transmitted to the gNB, the nr-gnb component parses the payload using the vulnerable function. The logic fails to verify the size or integrity of the dedicatedNASMessage argument before performing memory operations, such as copying data into a fixed-size buffer or performing pointer arithmetic. This lack of validation facilitates a buffer overflow or an out-of-bounds write condition.\nThe attack flow proceeds as follows: An attacker sends a maliciously constructed RRC ULInformationTransfer message over the network interface monitored by the nr-gnb component. The handler.cpp implementation receives this packet and proceeds to extract the dedicatedNASMessage field. Due to the absence of length constraints, the attacker-supplied payload exceeds the intended memory allocation. This triggers memory corruption, overwriting adjacent memory structures on the heap or stack. Depending on the targeted memory region, this can corrupt function pointers, return addresses, or application-specific state variables.\nSince UERANSIM is designed to simulate 5G RAN (Radio Access Network) infrastructure, the nr-gnb component is typically network-exposed to UEs (User Equipment). Because the vulnerability is triggered during the initial parsing of the RRC message, it requires no authentication or valid UE context establishment to execute. The attacker can force the gNB to process the malicious input as soon as a connection or signaling exchange is initiated.\nThe post-exploitation impact includes application crashes leading to a persistent Denial of Service (DoS) of the simulated gNB. Furthermore, if the corruption allows for controlled overwrites of execution flow, an attacker could achieve arbitrary code execution within the process space of the gNB. Because UERANSIM often runs in environments facilitating network simulation research, this vulnerability poses a significant risk to the integrity and availability of the simulated 5G environment."
}