PT-2026-5598 · Free5Gc · Free5Gc Pcf

Ziyulin

·

Published

2026-02-02

·

Updated

2026-02-02

·

CVE-2026-1739

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Free5GC PCF versions up to 1.4.1
Description A flaw exists in Free5GC PCF that could allow for a remote null pointer dereference. The issue is located in the HandleCreateSmPolicyRequest function within the internal/sbi/processor/smpolicy.go file. Exploitation of this issue has been publicly disclosed.
Recommendations Apply the patch with identifier df535f5524314620715e842baf9723efbeb481a7.

Exploit

Fix

NULL Pointer Dereference

Improper Resource Release

Weakness Enumeration

Related Identifiers

CVE-2026-1739

Affected Products

Free5Gc Pcf