PT-2026-38366 · Free5Gc+1 · Free5Gc+1
Sjna0414
·
Published
2026-05-07
·
Updated
2026-05-27
·
CVE-2026-42081
CVSS v3.1
7.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
free5GC versions prior to 4.2.2
Description
The Access and Mobility Management Function (AMF) in free5GC fails to verify UE Security Capabilities received in NGAP PathSwitchRequest messages against locally stored values. This occurs within the
handlePathSwitchRequestMain() function located in amf/internal/ngap/handler.go. A malicious gNB can overwrite the stored UE security capabilities with arbitrary values, which are then propagated in PathSwitchRequest Acknowledge and subsequent Handover Request messages. This leads to a persistent handover denial-of-service for affected UEs, as target gNBs may reject the procedure if the corrupted algorithms do not match their configured allowed algorithms.Recommendations
Update to version 4.2.2.
As a temporary workaround, restrict access to the
handlePathSwitchRequestMain() function or the associated NGAP PathSwitchRequest processing to trusted gNBs only.Exploit
Fix
Improperly Implemented Security Check for Standard
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Free5Gc
Github.Com/Free5Gc/Amf