PT-2026-21564 · Free5Gc+1 · Free5Gc+1
CVE-2025-69247
·
Publicado
2026-02-23
·
Atualizado
2026-02-28
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
free5GC go-upf versions prior to 1.2.8
Description
The go-upf component of free5GC, a User Plane Function (UPF) implementation for 5G networks, contains a Heap-based Buffer Overflow. A specially crafted PFCP Session Modification Request with an invalid SDF Filter length field can cause a heap buffer overflow, leading to a Denial of Service. This can crash the UPF network element, disrupting service for connected UEs and potentially causing cascading failures affecting the SMF. All deployments utilizing the free5GC UPF component may be affected.
Recommendations
Update to version 1.2.8 or later.
Exploit
Correção
DoS
Heap Based Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Free5Gc
Go-Upf