CVE-2025-56394
7.5free5gc · free5gc
Free5gc 4.0.1 contains a buffer overflow vulnerability in the AMF component due to improper validation of 5GS mobile identity, leading to a slice reference overflow.
Executive summary
A buffer overflow vulnerability in the free5gc AMF component allows unauthenticated attackers to trigger a denial of service condition.
Vulnerability
This is a buffer overflow vulnerability caused by incorrect validation of the 5GS mobile identity within the Access and Mobility Management Function (AMF). The flaw allows an unauthenticated, remote attacker to trigger a slice reference overflow, resulting in service disruption.
Business impact
Successful exploitation of this vulnerability results in a denial of service for the affected AMF, which is a critical component of the 5G core network. Given the CVSS score of 7.5, this high severity flaw poses a significant risk to network availability and operational continuity. Organizations relying on this software for 5G infrastructure may face total service outages if the AMF crashes under attack.
Remediation
Immediate Action: Monitor official free5gc channels for the release of a security patch and apply it as soon as it becomes available.
Proactive Monitoring: Review system logs for unusual AMF crash patterns or unexpected traffic directed at the mobile identity validation service.
Compensating Controls: Implement network-level rate limiting and traffic inspection to identify and block malformed 5GS mobile identity packets before they reach the AMF.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the referenced GitHub Gist.
Analyst recommendation
Due to the critical nature of the AMF in 5G core operations, this vulnerability requires immediate attention. Security teams should prioritize identifying instances of free5gc 4.0.1 within their environments and prepare for an urgent patch deployment once the vendor releases a fix. Until a patch is available, network segmentation and strict input validation via perimeter defenses are essential to mitigate the risk of a denial of service attack.