Impact
The vulnerability is a race condition in Free5GC's GMM Handler implementation in handler.go, affecting versions up to 4.2.3. The race can be triggered by concurrent manipulation of internal state, allowing an attacker to cause unintended behavior such as denial of service or, in the worst case, unauthorized access. This flaw is classified as CWE-362.
Affected Systems
Free5GC, specifically the AMF component that implements the GMM handler, is affected. Any installation of Free5GC version 4.2.3 or earlier is vulnerable. The vulnerability exists in the file /corefuzzer_deps/free5gc/NFs/amf/internal/gmm/handler.go. No other Free5GC components are listed as affected.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate risk. The EPSS score is not available, and the vulnerability has not been listed in the CISA KEV catalog, suggesting there is no known exploitation in the wild yet. Attackers can initiate the race condition remotely, so it is essential to patch promptly to reduce the probability of successful exploitation.
OpenCVE Enrichment