A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a specially crafted PFCP Session Establishment Request with a CreatePDR that contains a malformed Flow-Description is not robustly validated. The Flow-Description parser (parseFlowDesc) can read beyond the bounds of the provided buffer, causing a panic and terminating the UPF process. An attacker who can send PFCP Session Establishment Request messages to the UPF's N4/PFCP endpoint can exploit this issue to repeatedly crash the UPF.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 07 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Opennetworking
Opennetworking upf
CPEs cpe:2.3:a:opennetworking:upf:2.1.3:dev:*:*:*:*:*:*
Vendors & Products Opennetworking
Opennetworking upf

Sun, 21 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Omec-project
Omec-project upf
Vendors & Products Omec-project
Omec-project upf

Fri, 19 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Description A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a specially crafted PFCP Session Establishment Request with a CreatePDR that contains a malformed Flow-Description is not robustly validated. The Flow-Description parser (parseFlowDesc) can read beyond the bounds of the provided buffer, causing a panic and terminating the UPF process. An attacker who can send PFCP Session Establishment Request messages to the UPF's N4/PFCP endpoint can exploit this issue to repeatedly crash the UPF.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-12-19T18:01:12.206Z

Reserved: 2025-11-18T00:00:00.000Z

Link: CVE-2025-65567

cve-icon Vulnrichment

Updated: 2025-12-19T17:30:45.503Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-18T19:16:34.190

Modified: 2026-01-07T21:06:42.410

Link: CVE-2025-65567

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-21T21:14:58Z

Weaknesses