What is CVE-2024-14042?
A stack-based buffer overflow vulnerability was discovered in Open5GS up to version 2.7.1, affecting the Diameter S6a interface. The flaw exists in the `hss_ogs_diam_s6a_air_cb`/`hss_ogs_diam_s6a_ulr_cb` functions in `src/hss/hss-s6a-path.c` via manipulation of the `os.len` argument. Exploitation may lead to remote code execution, and immediate upgrade is recommended.
Azərbaycanca: Open5GS-in 2.7.1-ə qədər versiyalarında Diameter S6a interfeysində stack-based buffer overflow zəifliyi aşkarlanıb. `hss_ogs_diam_s6a_air_cb`/`hss_ogs_diam_s6a_ulr_cb` funksiyalarında `os.len` arqumentinin manipulyasiyası nəticəsində yaranır. İstismar uzaqdan kod icrasına səbəb ola bilər, dərhal yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Open5GS
FAQ2
Which versions of Open5GS are affected by CVE-2024-14042?
This vulnerability affects Open5GS versions up to 2.7.1.
In which interface does CVE-2024-14042 cause a stack-based buffer overflow?
The vulnerability is found in the Diameter S6a interface, specifically in the `hss_ogs_diam_s6a_air_cb`/`hss_ogs_diam_s6a_ulr_cb` functions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.