Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mosaic5g:flexric:2.0.0:*:*:*:*:*:*:* |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mosaic5g
Mosaic5g flexric |
|
| Vendors & Products |
Mosaic5g
Mosaic5g flexric |
Tue, 02 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Unauthenticated Process Crash via Null Dereference in FlexRIC Subscription Request |
Tue, 02 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 01 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Unauthenticated Process Crash via Null Dereference in FlexRIC Subscription Request | |
| Weaknesses | CWE-476 |
Mon, 01 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lookup function returns NULL, which is enforced by assert() in Debug builds (SIGABRT) and dereferenced in Release builds (SIGSEGV). A remote unauthenticated attacker can crash the iApp process (port 36422) by sending a subscription request with an arbitrary global_e2_node_id. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-02T15:26:33.673Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-37226
Updated: 2026-06-02T15:26:28.456Z
Status : Analyzed
Published: 2026-06-01T19:16:33.080
Modified: 2026-06-03T17:16:40.340
Link: CVE-2026-37226
No data.
OpenCVE Enrichment
Updated: 2026-06-02T20:55:23Z