PT-2026-21591 · Free5Gc · Free5Gc Smf

Linziyuu

·

Publicado

2026-02-24

·

Atualizado

2026-03-01

·

CVE-2026-26025

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions free5GC SMF versions up to and including 1.4.1
Description free5GC SMF provides the Session Management Function for free5GC, an open-source project for 5G mobile core networks. The software experiences a panic and terminates when processing a malformed PFCP SessionReportRequest on the PFCP (UDP/8805) interface. The issue occurs when receiving a malformed message via the PFCP interface, specifically a SessionReportRequest. No upstream fix is currently available. Mitigation strategies include restricting access to the PFCP interface to trusted UPF IPs, dropping or inspecting malformed PFCP SessionReportRequest messages at the network edge, or adding recover() around PFCP handler dispatch to prevent complete process termination.
Recommendations free5GC SMF versions up to and including 1.4.1: Apply ACL/firewall rules to the PFCP interface to allow only trusted UPF IPs to connect. free5GC SMF versions up to and including 1.4.1: Drop or inspect malformed PFCP SessionReportRequest messages at the network edge. free5GC SMF versions up to and including 1.4.1: Add recover() around PFCP handler dispatch to avoid whole-process termination as a mitigation.

Exploit

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-26025
GHSA-VW8R-P7H3-G3XH

Produtos afetados

Free5Gc Smf