VYPR
High severity7.5OSV Advisory· Published Dec 18, 2025· Updated Jun 17, 2026

CVE-2025-65559

CVE-2025-65559

Description

An issue was discovered in Open5GS 2.7.5-49-g465e90f, when processing a PFCP Session Establishment Request (type=50), the UPF crashes with a reachable assertion in lib/pfcp/context.c (ogs_pfcp_object_teid_hash_set) if the CreatePDR?PDI?F-TEID has CH=1 and the F-TEID address-family flag(s) (IPv4/IPv6) do not match the GTP-U resource family configured for the selected DNN (Network Instance), resulting in a denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Open5gs/Open5gsOSV3 versions
    v0.1.0, v0.1.1, v0.2.0, …+ 2 more
    • (no CPE)range: v0.1.0, v0.1.1, v0.2.0, …
    • cpe:2.3:a:open5gs:open5gs:2.7.5:*:*:*:*:*:*:*
    • (no CPE)range: 2.7.5-49-g465e90f

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.