PT-2026-21564 · Free5Gc+1 · Free5Gc+1

CVE-2025-69247

·

Publicado

2026-02-23

·

Atualizado

2026-02-28

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions free5GC go-upf versions prior to 1.2.8
Description The go-upf component of free5GC, a User Plane Function (UPF) implementation for 5G networks, contains a Heap-based Buffer Overflow. A specially crafted PFCP Session Modification Request with an invalid SDF Filter length field can cause a heap buffer overflow, leading to a Denial of Service. This can crash the UPF network element, disrupting service for connected UEs and potentially causing cascading failures affecting the SMF. All deployments utilizing the free5GC UPF component may be affected.
Recommendations Update to version 1.2.8 or later.

Exploit

Correção

DoS

Heap Based Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-69247
GHSA-GF69-93XR-P23G

Produtos afetados

Free5Gc
Go-Upf