PT-2026-38367 · Free5Gc+1 · Free5Gc+1

Sjna0414

·

Published

2026-05-07

·

Updated

2026-05-29

·

CVE-2026-42082

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions free5GC versions prior to 4.2.2
Description The Access and Mobility Management Function (AMF) in free5GC fails to enforce concurrent security procedure rules. Specifically, the AMF does not verify if an N2 handover procedure is ongoing before initiating a NAS Security Mode Command, and conversely, does not check for an ongoing NAS Security Mode Command before starting N2 procedures. This lack of synchronization can result in mismatches between the Non-Access Stratum (NAS) and Access Stratum (AS) security contexts in the network and the User Equipment (UE). Technical exploitation involves the SecurityMode() function in internal/gmm/sm.go and the handleHandoverRequiredMain() function in internal/ngap/handler.go, where required cross-procedure checks are missing.
Recommendations Update to version 4.2.2. As a temporary workaround, restrict the use of the SecurityMode() function and the handleHandoverRequiredMain() function to ensure they do not execute concurrently for the same UE.

Exploit

Fix

Improperly Implemented Security Check for Standard

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42082
GHSA-VRRX-58H3-PRMH

Affected Products

Free5Gc
Github.Com/Free5Gc/Amf