


Perceptive Security
SOC/SIEM Consultancy

FlexRIC v2.0.0 crashes when an SCTP association is closed before an E2_SETUP_REQUEST is sent. The near-RT RIC assumes a mapping between SCTP association and E2 …
Published:
31 May 2026 at 22:00:00
Alert date:
1 June 2026 at 18:04:01
Source:
nvd.nist.gov
Network Infrastructure, Critical Infrastructure
FlexRIC v2.0.0 contains a denial of service vulnerability where the near-RT RIC crashes when an SCTP association is closed before an E2_SETUP_REQUEST is sent. The application incorrectly assumes a mapping between SCTP association and E2 node always exists in the cleanup path and enforces this via assert(). A remote unauthenticated attacker can exploit this by completing an SCTP handshake on port 36421 and immediately disconnecting without sending any E2AP message, causing the near-RT RIC to crash. This vulnerability affects the 5G RAN Intelligent Controller component used in O-RAN networks.
Technical details
Mitigation steps:
Affected products:
FlexRIC
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-37220
https://github.com/MinamiKotor1/oran-security-advisories-zhongnan-luo/blob/main/advisories/CVE-2026-37220.md
https://gitlab.eurecom.fr/mosaic5g/flexric
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
