Home

Description

FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST with an empty ricEventTriggerDefinition field. The E42 layer decoder accepts this as valid, but the E2AP encoder asserts a non-empty constraint when forwarding the request. A remote unauthenticated attacker can crash the iApp process (port 36422) via SIGABRT by exploiting this cross-layer validation mismatch.

PUBLISHED Reserved 2026-04-06 | Published 2026-06-01 | Updated 2026-06-01 | Assigner mitre

References

gitlab.eurecom.fr/mosaic5g/flexric

github.com/...nan-luo/blob/main/advisories/CVE-2026-37225.md

cve.org (CVE-2026-37225)

nvd.nist.gov (CVE-2026-37225)

Download JSON