CVE-2026-1973: Free5GC SMF establishPfcpSession null pointer dereference
A vulnerability was determined in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the component SMF. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. It is best practice to apply a patch to resolve this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1973?
CVE-2026-1973 has a severity rating that indicates it poses a risk of null pointer dereference in Free5GC versions up to 4.1.0.
How do I fix CVE-2026-1973?
To fix CVE-2026-1973, upgrade your Free5GC installation to a version later than 4.1.0.
What component is affected by CVE-2026-1973?
CVE-2026-1973 affects the establishPfcpSession function of the SMF component in Free5GC.
Can CVE-2026-1973 be exploited remotely?
Yes, CVE-2026-1973 can be exploited remotely, making it potentially dangerous.
What versions of Free5GC are impacted by CVE-2026-1973?
Free5GC versions up to and including 4.1.0 are impacted by CVE-2026-1973.