QSearchQSearch

CVE-2026-37226

7.5 HIGH

FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node

Published: 2026-06-01 · Last updated: 2026-06-03

Severity and scoring

CVSS
7.5 HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE
CWE-476

Affected products

VendorProduct
mosaic5gflexric

Description

FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lookup function returns NULL, which is enforced by assert() in Debug builds (SIGABRT) and dereferenced in Release builds (SIGSEGV). A remote unauthenticated attacker can crash the iApp process (port 36422) by sending a subscription request with an arbitrary global_e2_node_id.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-37234 FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SETUP_REQUESTs (8.2 HIGH)
  • CVE-2026-37235 FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association (7.5 HIGH)
  • CVE-2026-37233 FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism (7.5 HIGH)
  • CVE-2026-37231 FlexRIC v2.0.0 uses a uint16_t counter for xapp_id assignment but stores the value in uint32_t message fields (7.5 HIGH)
  • CVE-2026-37230 FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does not exist in its registry (7.5 HIGH)

Same CWE

  • CVE-2025-7018 Null pointer dereference vulnerability in Avira Antivirus engine when scanning a malformed Windows PE file may allow Denial-of-Service of... (5.5 MEDIUM)
  • CVE-2026-53463 ImageMagick is free and open-source software used for editing and manipulating digital images (4.3 MEDIUM)
  • CVE-2026-24716 A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions
  • CVE-2026-22899 A NULL pointer dereference vulnerability has been reported to affect File Station 6 (6.5 MEDIUM)
  • CVE-2025-66281 A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions