PT-2026-38366 · Free5Gc+1 · Free5Gc+1

Sjna0414

·

Published

2026-05-07

·

Updated

2026-05-27

·

CVE-2026-42081

CVSS v3.1

7.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions free5GC versions prior to 4.2.2
Description The Access and Mobility Management Function (AMF) in free5GC fails to verify UE Security Capabilities received in NGAP PathSwitchRequest messages against locally stored values. This occurs within the handlePathSwitchRequestMain() function located in amf/internal/ngap/handler.go. A malicious gNB can overwrite the stored UE security capabilities with arbitrary values, which are then propagated in PathSwitchRequest Acknowledge and subsequent Handover Request messages. This leads to a persistent handover denial-of-service for affected UEs, as target gNBs may reject the procedure if the corrupted algorithms do not match their configured allowed algorithms.
Recommendations Update to version 4.2.2. As a temporary workaround, restrict access to the handlePathSwitchRequestMain() function or the associated NGAP PathSwitchRequest processing to trusted gNBs only.

Exploit

Fix

Improperly Implemented Security Check for Standard

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42081
GHSA-77X9-RF64-92GV

Affected Products

Free5Gc
Github.Com/Free5Gc/Amf