CVE-2026-75894: Osmocom Osmo-Iuh
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash and remote denial of service.
Affected products
- Osmocom Osmo-Iuh: from 0.1.0, before 1.8.0 (fixed in 1.8.0)
Published 2026-09-18. Last modified 2026-09-21.