CVE-2026-30056: Null Pointer Dereference
Published Aug 27, 2026
·Updated
A NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted NGAP messages during the initialization of a new RAN connection.
Affected Software
1 affected component
Free5GC=4.0.1
Event History
Aug 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:17 PM
Description
Frequently Asked Questions
1
Who can exploit this issue?
An attacker able to establish or initialize a new RAN connection to the AMF and send crafted NGAP messages can trigger the denial of service.
2
What is the impact of successful exploitation?
Successful exploitation causes a NULL pointer dereference in the AMF NGAP Dispatcher, resulting in a denial of service.
3
Which version is identified as affected?
The reported affected version is free5gc v4.0.1.