Session Management Function Vulnerability in free5GC by free5GC
CVE-2026-25501

6.6MEDIUM

Key Information:

Vendor

Free5gc

Status
Vendor
CVE Published:
24 February 2026

What is CVE-2026-25501?

The Session Management Function (SMF) of free5GC, which facilitates session management in 5G mobile core networks, is prone to a nil pointer dereference issue triggered by malformed PFCP SessionReportRequest messages on the SMF PFCP interface (UDP/8805). This vulnerability can result in the unexpected termination of the SMF process, significantly impacting network functionality. Although an upstream fix is not available, several mitigations can be implemented, such as restricting access to the PFCP interface to trusted UPF IPs, filtering malformed messages at the network edge, and employing error recovery mechanisms in the PFCP handler to prevent complete process failure.

Affected Version(s)

smf <= 1.4.1

References

CVSS V4

Score:
6.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.