CVE-2025-66720: Null Pointer Dereference
Published Jan 23, 2026
·Updated
Null pointer dereference in free5gc pcf 1.4.0 in file internal/sbi/processor/ampolicy.go in function HandleDeletePoliciesPolAssoId.
Affected Software
2 affected components
free5gc/pcf
free5gc pcf=1.4.0
Remediation
Patch Available
Event History
Jan 23, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-66720?
CVE-2025-66720 is classified as a medium severity vulnerability due to the potential for denial of service.
2
What is the impact of CVE-2025-66720?
CVE-2025-66720 can lead to a null pointer dereference, causing service interruptions in free5gc pcf.
3
How do I fix CVE-2025-66720?
To fix CVE-2025-66720, update to the latest version of free5gc pcf where the vulnerability is addressed.
4
Is CVE-2025-66720 present in previous versions of free5gc pcf?
Yes, CVE-2025-66720 is present in free5gc pcf version 1.4.0 and potentially earlier versions.
5
How can I mitigate the effects of CVE-2025-66720?
Mitigation for CVE-2025-66720 includes implementing strict input validation and updating to a patched version as soon as possible.