Description
A vulnerability was determined in Free5GC up to 4.2.3. This vulnerability affects unknown code of the file /corefuzzer_deps/free5gc/NFs/amf/internal/gmm/handler.go of the component Gmm Handler. This manipulation causes race condition. The attack can be initiated remotely. Patch name: e323b01464355781b8b8d5dd695e05cbc00a62f2. To fix this issue, it is recommended to deploy a patch.
Published: 2026-09-20
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Race Condition Exploitation
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a race condition in Free5GC's GMM Handler implementation in handler.go, affecting versions up to 4.2.3. The race can be triggered by concurrent manipulation of internal state, allowing an attacker to cause unintended behavior such as denial of service or, in the worst case, unauthorized access. This flaw is classified as CWE-362.

Affected Systems

Free5GC, specifically the AMF component that implements the GMM handler, is affected. Any installation of Free5GC version 4.2.3 or earlier is vulnerable. The vulnerability exists in the file /corefuzzer_deps/free5gc/NFs/amf/internal/gmm/handler.go. No other Free5GC components are listed as affected.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate risk. The EPSS score is not available, and the vulnerability has not been listed in the CISA KEV catalog, suggesting there is no known exploitation in the wild yet. Attackers can initiate the race condition remotely, so it is essential to patch promptly to reduce the probability of successful exploitation.

Generated by OpenCVE AI on September 20, 2026 at 19:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official patch commit e323b01464355781b8b8d5dd695e05cbc00a62f2 to the Free5GC source code, updating gmm/handler.go.
  • Rebuild the AMF component and redeploy it so the updated binary is in use.
  • Restart the AMF service.

Generated by OpenCVE AI on September 20, 2026 at 19:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Free5GC up to 4.2.3. This vulnerability affects unknown code of the file /corefuzzer_deps/free5gc/NFs/amf/internal/gmm/handler.go of the component Gmm Handler. This manipulation causes race condition. The attack can be initiated remotely. Patch name: e323b01464355781b8b8d5dd695e05cbc00a62f2. To fix this issue, it is recommended to deploy a patch.
Title Free5GC Gmm handler.go race condition
First Time appeared Free5gc
Free5gc free5gc
Weaknesses CWE-362
CPEs cpe:2.3:a:free5gc:free5gc:*:*:*:*:*:*:*:*
Vendors & Products Free5gc
Free5gc free5gc
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T19:50:05.024Z

Reserved: 2026-09-19T21:20:27.268Z

Link: CVE-2026-94043

cve-icon Vulnrichment

Updated: 2026-09-21T19:49:41.089Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T19:17:12.780

Modified: 2026-09-21T20:17:40.040

Link: CVE-2026-94043

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:30:04Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')