A vulnerability described as critical has been identified in Open5GS up to 2.7.1. This vulnerability affects the function
mme_s6a_subscription_data_from_avp of the file src/mme/mme-fd-path.c of the component Diameter S6a Interface. Executing a manipulation of the argument msisdn_len can lead to heap-based buffer overflow.
This vulnerability is registered as CVE-2024-14043. It is possible to launch the attack remotely. Furthermore, an exploit is available.
Upgrading the affected component is recommended.