CVE-2026-30069: Null Pointer Dereference
Published Aug 27, 2026
·Updated
A NULL pointer dereference in the UDMC registration handler component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload.
Affected Software
1 affected component
free5gc UDMC registration handler component=4.0.1
Event History
Aug 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:17 PM
Description
Frequently Asked Questions
1
Are versions other than v4.0.1 confirmed to be affected?
The available information identifies free5gc v4.0.1 only. It does not provide an affected-version range or a fixed version.
2
What attacker access or authentication requirements are known?
The available information states that a crafted payload can trigger the issue in the UDMC registration handler. It does not specify authentication requirements, network exposure, or user-interaction prerequisites.
3
Is a temporary mitigation documented for environments that cannot patch immediately?
No workaround or mitigation is provided in the available information.