PT-2026-39258 · Unknown · Free5Gc Smf

Linziyuu

·

Published

2026-05-08

·

Updated

2026-06-17

·

CVE-2026-44328

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions free5GC SMF version 4.2.1
Description The SMF mounts the UPI management route group without inbound OAuth2 middleware, allowing unauthenticated access. A flaw in the DeleteUpNodeLink function causes a nil-pointer dereference when processing requests for Access Network (AN) typed nodes, as these nodes are constructed without a UPF object. Specifically, the handler calls upNode.UPF.CancelAssociation() unconditionally, leading to a panic. Furthermore, the UpNodeDelete(upNodeRef) function is executed before the panic occurs, resulting in the mutation of the in-memory user-plane topology. An off-path network attacker can exploit this by sending a DELETE request to the endpoint "/upi/v1/upNodesLinks/{upNodeRef}" using the upNodeRef variable, which can delete arbitrary named entries and deny the SMF's ability to use those nodes for legitimate sessions.
Recommendations Update free5GC SMF to a version that incorporates the fix from pull request 199. As a temporary workaround, restrict network access to the SMF SBI interface to authorized sources only to prevent unauthenticated access to the "/upi/v1/upNodesLinks/" endpoint.

Exploit

Fix

DoS

Missing Authentication

Missing Authorization

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44328
GHSA-P9MG-74MG-CWWR

Affected Products

Free5Gc Smf