PT-2026-26186 · Linux Foundation · Free5Gc

Zfei10990-Cmd

·

Published

2026-03-18

·

Updated

2026-03-27

·

CVE-2026-33064

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Free5GC versions prior to 1.4.2
Description Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2 are susceptible to a procedure panic caused by a Nil Pointer Dereference in the /sdm-subscriptions API endpoint. A remote attacker can cause the UDM service to panic and crash by sending a crafted POST request to the /sdm-subscriptions endpoint with a malformed URL path containing path traversal sequences (../) and a large JSON payload. The DataChangeNotificationProcedure function in notifier.go attempts to access a nil pointer without proper validation, resulting in a complete service crash. Exploitation leads to disruption of UDM functionality until recovery via restart.
Recommendations Upgrade to Free5GC version 1.4.2 or later.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2026-33064
GHSA-7G27-V5WJ-JR75
GO-2026-4757
SUSE-SU-2026:1135-1

Affected Products

Free5Gc