CVE-2025-63679: Buffer Overflow
Published Nov 12, 2025
·Updated
free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP message from a gNB, the AMF process crashes.
Affected Software
2 affected components
free5gc Free5gc<4.1.0
free5gc Free5gc<=4.1.0
Event History
Nov 12, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-63679?
CVE-2025-63679 is classified as a high severity vulnerability due to the potential for crashing the AMF process.
2
How do I fix CVE-2025-63679?
To fix CVE-2025-63679, update free5gc to version 4.1.1 or later where the buffer overflow issue is resolved.
3
What systems are affected by CVE-2025-63679?
CVE-2025-63679 affects free5gc versions up to and including 4.1.0.
4
What type of vulnerability is CVE-2025-63679?
CVE-2025-63679 is a buffer overflow vulnerability that can cause the AMF to crash.
5
What impact does CVE-2025-63679 have on services?
CVE-2025-63679 can lead to service disruptions as the AMF process crashes when processing certain NGAP messages.