Authentication State Vulnerabilities in free5GC's AUSF Component by free5GC
CVE-2026-55784
What is CVE-2026-55784?
The AUSF component of free5GC, an open-source implementation of the 5G core network, is susceptible to vulnerabilities arising from improper handling of subscriber authentication states. In affected versions, the AUSF component's global sync.Map, known as AUSFContext.UePool, inadequately manages the authentication states by coupling them solely to the SUPI, which can lead to unintentional overwrites of active authentication contexts. Attackers with access to the AUSF SBI/N12 interface could exploit this by initiating multiple concurrent POST requests for the same SUPI, thereby disrupting the authentication process. This flaw not only prevents the validation of correct EAP-AKA' responses but also denies access for the targeted subscriber amidst ongoing request floods. As of now, there are no fixed versions available to address this vulnerability.
Affected Version(s)
free5gc <= 1.4.4
