Sploitus

Exploit for NULL Pointer Dereference in Linux Linux Kernel

githubexploit · 2026-08-05

Exploit Code

README55 lines
## https://sploitus.com/exploit?id=3A4FA7D9-5C42-50CF-8E4C-8A512EDA8EA9
---

## CVE-2026-23002 – 5G NAS Message Buffer Overflow in gNodeB

### Program Code (C simulation)

```c
// gnb_nas_sim.c - Simulated 5G gNodeB parsing NAS Registration Request
#include 
#include 
#include 

#define MAX_IE_SIZE 128

void process_registration_request(uint8_t *nas_msg, uint16_t length) {
    uint8_t ie_buffer[MAX_IE_SIZE];
    // Read IE length from message; if length > MAX_IE_SIZE, buffer overflow
    uint16_t ie_length = (nas_msg[0]  0 && ie_length <= length - 2) {
        memcpy(ie_buffer, nas_msg + 2, ie_length); // no bounds check!
        printf("IE copied, size %d\n", ie_length);
    }
}

int main() {
    // Craft a NAS message with an oversized IE length
    uint8_t attack[] = {0x01, 0x00}; // IE length = 256, but buffer is only 128 bytes
    // Append padding to make length consistent
    memset(attack+2, 'A', 254);
    process_registration_request(attack, sizeof(attack));
    return 0;
}

```

# CVE-2026-23002 – 5G NAS Message Buffer Overflow in gNodeB

![Severity: Critical](https://img.shields.io/badge/severity-critical-red)

## Overview
The 5G Non‑Access Stratum (NAS) parser in a simulated gNodeB fails to validate the Information Element length field. An attacker sending a crafted Registration Request can overflow a stack buffer, leading to remote code execution on the base station.

## Vulnerability Details
- **Type:** Stack Buffer Overflow
- **Impact:** Full base station compromise, network disruption.
- **Root Cause:** The NAS IE length is trusted without bound checking against the destination buffer size.

## Exploit Demonstration
Compile and run the vulnerable parser:
```bash
gcc -o gnb_nas_sim gnb_nas_sim.c -fno-stack-protector
./gnb_nas_sim
```

The program crashes with a segmentation fault (stack corruption).