PT-2025-52290 · Unknown · Omec-Project Upf

Linziyuu

·

Published

2025-12-18

·

Updated

2025-12-20

·

CVE-2025-65567

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions omec-project UPF versions up to 2.1.3-dev
Description A flaw exists in the omec-project UPF (pfcpiface component) that can lead to a denial-of-service condition. Specifically, a crafted PFCP Session Establishment Request, containing a malformed Flow-Description, is not adequately validated. The parseFlowDesc function can read beyond the allocated buffer, resulting in a process termination. An attacker capable of sending PFCP Session Establishment Request messages to the UPF’s N4/PFCP endpoint can exploit this to repeatedly crash the UPF process. The vulnerable component is the pfcpiface component.
Recommendations Update to a version beyond 2.1.3-dev.

Exploit

Fix

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2025-65567

Affected Products

Omec-Project Upf