Description
A NULL pointer dereference in the UDMC registration handler component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload.
Published: 2026-08-27
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The vulnerability is a NULL pointer dereference in the UDMC registration handler component of free5gc version 4.0.1. An attacker can send a crafted registration message that causes the service to dereference a null pointer, leading to a crash and resulting in a denial of service. This flaw is a classic example of CWE‑476.

Affected Systems

The affected product is the free5gc open‑source 5G core implementation, specifically version 4.0.1. No official CNA vendors are listed, but the known reference indicates the issue exists in the free5gc codebase. Systems running this version without the fix are susceptible to the described DoS.

Risk and Exploitability

The CVSS score of 7.5 demonstrates that the vulnerability carries high severity, while an EPSS score of less than 1% indicates a low probability of active exploitation at present. The vulnerability is not listed in CISA's KEV catalog, suggesting no publicly observed exploits yet. Nevertheless, the DoS impact could be significant for networks relying on free5gc in production environments. The attack vector is inferred to be remote via the network interfaces that handle registration messages, as the flaw is triggered by crafted payload data. If exploited, the target service would crash, disrupting 5G core operations until the component is restarted or replaced.

Generated by OpenCVE AI on August 31, 2026 at 17:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade free5gc to a patched version (e.g., 4.0.2 or later) that addresses the NULL pointer dereference in the UDMC registration handler.
  • If an immediate upgrade is not possible, temporarily block or throttle incoming UDMC registration requests to mitigate the risk of service crashes.
  • Consider disabling the UDMC component or restricting its network access while monitoring for anomalous registration traffic until a patch can be applied.

Generated by OpenCVE AI on August 31, 2026 at 17:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title NULL Pointer Dereference in free5gc UDMC Registration Handler Causes DoS

Mon, 31 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title NULL Pointer Dereference in free5gc UDMC Registration Handler Causes DoS
First Time appeared Free5gc
Free5gc free5gc
Weaknesses CWE-476
Vendors & Products Free5gc
Free5gc free5gc

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description A NULL pointer dereference in the UDMC registration handler component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T16:09:07.761Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-30069

cve-icon Vulnrichment

Updated: 2026-08-31T16:08:58.500Z

cve-icon NVD

Status : Deferred

Published: 2026-08-27T17:17:51.973

Modified: 2026-08-31T20:59:32.817

Link: CVE-2026-30069

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T18:00:03Z

Weaknesses