Description
A vulnerability was identified in Free5GC up to 4.1.0. This affects the function ResolveNodeIdToIp of the file internal/sbi/processor/datapath.go of the component SMF. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is recommended to apply a patch to fix this issue.
Problem types
Timeline
| 2026-02-05: | Advisory disclosed |
| 2026-02-05: | VulDB entry created |
| 2026-02-05: | VulDB entry last update |
Credits
ZiyuLin (VulDB User)
References
vuldb.com/?id.344496 (VDB-344496 | Free5GC SMF datapath.go ResolveNodeIdToIp denial of service)
vuldb.com/?ctiid.344496 (VDB-344496 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.743237 (Submit #743237 | free5gc SMF v4.1.0 Denial of Service)
github.com/free5gc/free5gc/issues/816
github.com/free5gc/free5gc/issues/816
github.com/free5gc/smf/pull/189
github.com/free5gc/free5gc/