CVE-2024-37877: Ueranism

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

UERANSIM before 3.2.6 allows out-of-bounds read when a RLS packet is sent to gNodeB with malformed PDU length. This occurs in function readOctetString in src/utils/octet_view.cpp and in function DecodeRlsMessage in src/lib/rls/rls_pdu.cpp

Affected products

  • Ueranism Ueranism: before 3.2.6 (fixed in 3.2.6)

Published 2024-06-13. Last modified 2026-06-17.