


Perceptive Security
SOC/SIEM Consultancy

FlexRIC v2.0.0 crashes when receiving a RIC_SUBSCRIPTION_RESPONSE with an unknown ric_id that has no corresponding pending event. The near-RT RIC uses assert() …
Published:
31 May 2026 at 22:00:00
Alert date:
1 June 2026 at 18:04:01
Source:
nvd.nist.gov
Network Infrastructure, Critical Infrastructure
FlexRIC v2.0.0 contains a vulnerability where the near-RT RIC crashes when receiving a RIC_SUBSCRIPTION_RESPONSE with an unknown ric_id that has no corresponding pending event. The system uses assert() to enforce pending event existence during response processing. Remote unauthenticated attackers can exploit this by sending forged RIC_SUBSCRIPTION_RESPONSE messages to port 36421, causing SIGABRT in Debug builds or NULL pointer dereference (SIGSEGV) in Release builds. This represents a denial of service vulnerability in telecommunications infrastructure.
Technical details
Mitigation steps:
Affected products:
FlexRIC
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-37221
https://github.com/MinamiKotor1/oran-security-advisories-zhongnan-luo/blob/main/advisories/CVE-2026-37221.md
https://gitlab.eurecom.fr/mosaic5g/flexric
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
