CVE-2026-1682: Free5GC SMF PFCP UDP Endpoint handler.go HandlePfcpAssociationReleaseRequest null pointer dereference
A flaw has been found in Free5GC SMF up to 4.1.0. Affected is the function HandlePfcpAssociationReleaseRequest of the file internal/pfcp/handler/handler.go of the component PFCP UDP Endpoint. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The exploit has been published and may be used. A patch should be applied to remediate this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1682?
CVE-2026-1682 has been classified as a medium severity vulnerability due to the potential for service disruption caused by a null pointer dereference.
How do I fix CVE-2026-1682?
To fix CVE-2026-1682, update Free5GC SMF to version 4.1.1 or later where the vulnerability has been addressed.
What systems are affected by CVE-2026-1682?
CVE-2026-1682 affects Free5GC SMF versions up to and including 4.1.0.
What are the implications of CVE-2026-1682 exploitation?
Exploitation of CVE-2026-1682 could lead to service disruption in the Free5GC network infrastructure.
What component is involved in CVE-2026-1682?
CVE-2026-1682 involves the PFCP UDP Endpoint component of the Free5GC SMF.