PT-2026-26186 · Linux Foundation · Free5Gc
Zfei10990-Cmd
·
Published
2026-03-18
·
Updated
2026-03-27
·
CVE-2026-33064
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Free5GC versions prior to 1.4.2
Description
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2 are susceptible to a procedure panic caused by a Nil Pointer Dereference in the
/sdm-subscriptions API endpoint. A remote attacker can cause the UDM service to panic and crash by sending a crafted POST request to the /sdm-subscriptions endpoint with a malformed URL path containing path traversal sequences (../) and a large JSON payload. The DataChangeNotificationProcedure function in notifier.go attempts to access a nil pointer without proper validation, resulting in a complete service crash. Exploitation leads to disruption of UDM functionality until recovery via restart.Recommendations
Upgrade to Free5GC version 1.4.2 or later.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Free5Gc