CVE-2025-65559: High severity open5gs open5gs vulnerability
An issue was discovered in Open5GS 2.7.5-49-g465e90f, when processing a PFCP Session Establishment Request (type=50), the UPF crashes with a reachable assertion in lib/pfcp/context.c (ogspfcpobjectteidhashset) if the CreatePDR?PDI?F-TEID has CH=1 and the F-TEID address-family flag(s) (IPv4/IPv6) do not match the GTP-U resource family configured for the selected DNN (Network Instance), resulting in a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65559?
CVE-2025-65559 is considered to have a high severity due to the potential for Denial of Service through a UPF crash.
How do I fix CVE-2025-65559?
To fix CVE-2025-65559, you should upgrade Open5GS to the latest version that addresses the vulnerability.
What impact does CVE-2025-65559 have on Open5GS?
CVE-2025-65559 causes the User Plane Function (UPF) to crash, which can disrupt network connectivity.
Who is affected by CVE-2025-65559?
Any users of Open5GS version 2.7.5-49-g465e90f that process PFCP Session Establishment Requests are affected by CVE-2025-65559.
Is there a workaround for CVE-2025-65559?
Currently, the recommended solution for CVE-2025-65559 is to update the software, as there are no known workarounds to mitigate the crash.