Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.5

Free5GC UPF Crashes When Processing Malformed PFCP Request

CVE-2025-70122
Summary

A security issue affects the free5GC UPF component. An attacker could send a specially crafted message, causing the system to crash. Upgrade to a fixed version of free5GC to prevent this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
free5gc free5gc 4.0.1 –
Original title
A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted PFCP Session Modification Request. The issue occurs in...
Original description
A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted PFCP Session Modification Request. The issue occurs in the SDFFilterFields.UnmarshalBinary function (sdf-filter.go) when processing a declared length that exceeds the actual buffer capacity, leading to a runtime panic and UPF crash.
nvd CVSS3.1 7.5
Vulnerability type
CWE-122 Heap-based Buffer Overflow
Published: 13 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026