Denial of Service Vulnerability in free5GC by free5GC
CVE-2025-69232
What is CVE-2025-69232?
The free5GC project, which serves as an open-source solution for 5th generation (5G) mobile core networks, is susceptible to a vulnerability that arises from improper input validation and protocol compliance. Specifically, the versions of free5GC go-upf up to and including 1.2.6, along with corresponding free5GC smf versions up to and including 1.4.0, are affected. Attackers can exploit this vulnerability by sending malformed PFCP Association Setup Requests, which the User Plane Function (UPF) mistakenly accepts, leading to an inconsistent state. This disruption can cause legitimate requests to enter a reconnection loop with the Session Management Function (SMF) and degrade network services significantly. As of now, a patch is under development, and users are encouraged to apply it upon release for mitigation.
Affected Version(s)
go-upf <= 1.2.6
smf <= 1.4.0
