Description
A weakness has been identified in Free5GC up to 4.1.0. Affected is the function SessionDeletionResponse of the component SMF. This manipulation causes null pointer dereference. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. It is suggested to install a patch to address this issue.
Published: 2026-02-06
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

A null pointer dereference flaw exists in the SessionDeletionResponse function of the SMF component of Free5GC up to version 4.1.0. When an attacker sends a crafted message that triggers this code path, the SMF process can crash, potentially allowing a denial of service. The failure does not explicitly grant remote code execution or data exfiltration, but it does disrupt service availability for affected users.

Affected Systems

The vulnerability affects all Free5GC deployments running SMF version 4.1.0 or earlier. The affected component is the SMF (Session Management Function) of the Free5GC network function suite.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity vulnerability. The EPSS score of less than 1% suggests a low but non-zero likelihood of exploitation, yet public exploits are known to exist. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, but its remote nature and public exploit reduces confidence in the risk assessment. An attacker with network visibility to the SMF can trigger the flaw and cause an outage.

Generated by OpenCVE AI on April 17, 2026 at 22:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Free5GC patch that removes the null pointer dereference in SessionDeletionResponse or upgrades to a version newer than 4.1.0.
  • After applying the patch, restart the SMF process to ensure the fix takes effect.
  • Monitor SMF logs and network traffic for unexpected crashes or repeated session deletion requests to detect any potential exploitation attempts.

Generated by OpenCVE AI on April 17, 2026 at 22:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 09 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:free5gc:free5gc:*:*:*:*:*:*:*:*

Fri, 06 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Free5gc
Free5gc free5gc
Vendors & Products Free5gc
Free5gc free5gc

Fri, 06 Feb 2026 03:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Free5GC up to 4.1.0. Affected is the function SessionDeletionResponse of the component SMF. This manipulation causes null pointer dereference. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. It is suggested to install a patch to address this issue.
Title Free5GC SMF SessionDeletionResponse null pointer dereference
Weaknesses CWE-404
CWE-476
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T09:20:25.492Z

Reserved: 2026-02-05T13:33:54.329Z

Link: CVE-2026-1976

cve-icon Vulnrichment

Updated: 2026-02-06T19:33:58.302Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-06T03:15:49.503

Modified: 2026-02-09T15:04:08.463

Link: CVE-2026-1976

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T23:00:12Z

Weaknesses