Unrated severityNVD Advisory· Published Feb 6, 2026· Updated Feb 23, 2026
Free5GC SMF establishPfcpSession null pointer dereference
CVE-2026-1973
Description
A vulnerability was determined in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the component SMF. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. It is best practice to apply a patch to resolve this issue.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/free5gc/smf/pull/189mitreissue-trackingpatch
- github.com/free5gc/free5gc/issues/815mitreexploitissue-tracking
- vuldb.commitrethird-party-advisory
- github.com/free5gc/free5gc/issues/815mitreissue-tracking
- vuldb.commitresignaturepermissions-required
- vuldb.commitrevdb-entrytechnical-description
News mentions
0No linked articles in our index yet.