CVE-2026-1975: Free5GC pfcp_reports.go identityTriggerType null pointer dereference
A security flaw has been discovered in Free5GC up to 4.1.0. This impacts the function identityTriggerType of the file pfcpreports.go. The manipulation results in null pointer dereference. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. Applying a patch is advised to resolve this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1975?
CVE-2026-1975 is considered a critical vulnerability due to its potential for remote exploitation.
How do I fix CVE-2026-1975?
To fix CVE-2026-1975, upgrade Free5GC to version 4.1.1 or later, which addresses this null pointer dereference issue.
What impact does CVE-2026-1975 have on Free5GC?
CVE-2026-1975 can result in a denial of service due to a null pointer dereference in the identityTriggerType function.
Is CVE-2026-1975 exploitable remotely?
Yes, CVE-2026-1975 can be exploited remotely, allowing attackers to trigger the vulnerability from outside the network.
Which versions of Free5GC are affected by CVE-2026-1975?
CVE-2026-1975 affects all versions of Free5GC up to and including version 4.1.0.