Description
A weakness has been identified in Free5GC 4.1.0. Affected is the function HandleRegistrationComplete of the file internal/gmm/handler.go of the component AMF. Executing a manipulation can lead to denial of service. The attack may be performed from remote. This patch is called 52e9386401ce56ea773c5aa587d4cdf7d53da799. It is best practice to apply a patch to resolve this issue.
Problem types
Timeline
| 2026-03-21: | Advisory disclosed |
| 2026-03-21: | VulDB entry created |
| 2026-03-21: | VulDB entry last update |
Credits
shovon0203 (VulDB User)
References
github.com/free5gc/free5gc/issues/792
vuldb.com/?id.352319 (VDB-352319 | Free5GC AMF handler.go HandleRegistrationComplete denial of service)
vuldb.com/?ctiid.352319 (VDB-352319 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.774073 (Submit #774073 | Linux Foundation free5GC 4.1.0 Denial of Service)
github.com/free5gc/free5gc/issues/792
github.com/free5gc/amf/pull/198
github.com/...ommit/52e9386401ce56ea773c5aa587d4cdf7d53da799
github.com/free5gc/free5gc/