CVE-2025-65562: Out-of-bounds Read

Published Dec 18, 2025
·
Updated

The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker can send a request with a very large SEID (e.g., 0xFFFFFFFFFFFFFFFF) that causes an integer conversion/underflow in LocalNode.DeleteSess() / LocalNode.Sess() when a uint64 SEID is converted to int and used in index arithmetic. This leads to a negative index into n.sess and a Go runtime panic, resulting in a denial of service (UPF crash). The issue has been reproduced on free5GC v4.1.0 with crashes observed in the session lookup/deletion path in internal/pfcp/node.go; other versions may also be affected. No authentication is required.

Affected Software

2 affected components
free5GC/free5gc
free5gc Free5gc=4.1.0

Event History

Dec 18, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-65562?

CVE-2025-65562 is considered a high severity vulnerability due to its potential for unauthenticated remote exploitation.

2

How do I fix CVE-2025-65562?

To remediate CVE-2025-65562, ensure that you apply the latest security patches provided by free5GC for the affected version.

3

What type of attack can be executed with CVE-2025-65562?

An unauthenticated remote attacker can exploit CVE-2025-65562 to cause an integer conversion underflow through malicious PFCP Session Deletion Requests.

4

Which versions of free5GC are affected by CVE-2025-65562?

CVE-2025-65562 affects free5GC version 4.1.0 and potentially other versions if not patched.

5

What are the potential impacts of exploitation of CVE-2025-65562?

Exploitation of CVE-2025-65562 may lead to denial of service or other unexpected behavior due to improper handling of the SEID.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203