MEDIUM
Free5GC SMF PFCP UDP Endpoint handler.go HandlePfcpAssociationReleaseRequest null pointer dereference
Published Jan 30, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.75%
Description
A flaw has been found in Free5GC SMF up to 4.1.0. Affected is the function HandlePfcpAssociationReleaseRequest of the file internal/pfcp/handler/handler.go of the component PFCP UDP Endpoint. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The exploit has been published and may be used. A patch should be applied to remediate this issue.
Affected products
-
Affected
- 4.0
- 4.1.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-5030 Advisory
- https://github.com/free5gc/free5gc/issues/794 issue-trackingExploitIssue TrackingVendor Advisory
- https://github.com/free5gc/free5gc/issues/794#issue-3811888505 exploitissue-trackingIssue TrackingVendor Advisory
- https://github.com/free5gc/free5gc/issues/794#issuecomment-3761063382 issue-trackingIssue Tracking
- https://github.com/free5gc/smf/ product
- https://github.com/free5gc/smf/pull/188 issue-trackingpatchIssue Tracking
- https://vuldb.com/?ctiid.343475 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.343475 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.739508 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-5030 | Advisory | |
| https://github.com/free5gc/free5gc/issues/794 | issue-trackingExploitIssue TrackingVendor Advisory | |
| https://github.com/free5gc/free5gc/issues/794#issue-3811888505 | exploitissue-trackingIssue TrackingVendor Advisory | |
| https://github.com/free5gc/free5gc/issues/794#issuecomment-3761063382 | issue-trackingIssue Tracking | |
| https://github.com/free5gc/smf/ | product | |
| https://github.com/free5gc/smf/pull/188 | issue-trackingpatchIssue Tracking | |
| https://vuldb.com/?ctiid.343475 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.343475 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.739508 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jan 30, 2026
Updated Feb 23, 2026
Reserved Jan 30, 2026
Link CVE-2026-1682
CISA Vulnrichment
Updated Jan 30, 2026
Red Hat
No data
GitHub
No data