Session Management Function Vulnerability in free5GC by free5GC
CVE-2026-25501
6.6MEDIUM
What is CVE-2026-25501?
The Session Management Function (SMF) of free5GC, which facilitates session management in 5G mobile core networks, is prone to a nil pointer dereference issue triggered by malformed PFCP SessionReportRequest messages on the SMF PFCP interface (UDP/8805). This vulnerability can result in the unexpected termination of the SMF process, significantly impacting network functionality. Although an upstream fix is not available, several mitigations can be implemented, such as restricting access to the PFCP interface to trusted UPF IPs, filtering malformed messages at the network edge, and employing error recovery mechanisms in the PFCP handler to prevent complete process failure.
Affected Version(s)
smf <= 1.4.1
