CVE-2026-30072: Null Pointer Dereference
Published Aug 27, 2026
·Updated
A NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload.
Affected Software
1 affected component
free5gc Free5gc=4.0.1
Event History
Aug 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:17 PM
Description
Frequently Asked Questions
1
Who is exposed to this denial-of-service issue?
Deployments running free5gc v4.0.1 are affected when their CDR processing path can receive attacker-supplied payloads. The available information does not identify specific network exposure requirements or affected deployment roles.
2
What does an attacker need to do to trigger the issue?
An attacker needs to supply a crafted payload that reaches the CDR processing path. Processing that payload can trigger a NULL pointer dereference and cause a denial of service.