CVE-2026-44321
published 2026-05-27CVE-2026-44321: free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.36%
30.2th percentile
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. The POST /upi/v1/upNodesLinks create-or-update handler accepts attacker-controlled JSON and passes it directly into UpNodesFromConfiguration(), which calls logger.InitLog.Fatalf(...) on several validation failures. One confirmed path is the UE-IP-pool overlap check: a single unauthenticated POST that adds a new UPF whose pool overlaps an existing UPF terminates the entire SMF process (docker ps shows Exited (1)), not just the goroutine. This vulnerability is fixed in 4.2.2.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| free5gc | free5gc | < 4.2.2 | 4.2.2 |
| github.com | free5gc_smf | 0 – 1.4.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-16526 PCP: PCP: Privilege escalation to root via linux_sockets PMDA vulnerability
bugzilla·2026-07-22·CVSS 8.8
CVE-2026-16526 [HIGH] CVE-2026-16526 PCP: PCP: Privilege escalation to root via linux_sockets PMDA vulnerability
CVE-2026-16526 PCP: PCP: Privilege escalation to root via linux_sockets PMDA vulnerability
Summary: When the linux_sockets PMDA is loaded as a DSO inside PMCD, code execution
achieved via Vulnerability 3 (network.persocket.filter injection) can be escalated from user
pcp to root. The pmdarootfd Unix socket connection to pmdaroot is created without
O_CLOEXEC, causing all child processes spawned by popen() to inherit it. pmdaroot runs as
root and processes PDUROOT_STARTPMDA_REQ without per-request authentication,
executing attacker-controlled arguments via execvp() as root.
Prerequisites:
• Vulnerability 3 (linux_sockets command injection) required for initial code execution
- exploitable either locally via pmcd (TCP 44321, localhost only by default) or
remotely via the pmproxy REST API (TC
Bugzilla
CVE-2026-16529 PCP: PCP: Denial of Service due to signed integer overflow
bugzilla·2026-07-22·CVSS 7.5
CVE-2026-16529 [HIGH] CVE-2026-16529 PCP: PCP: Denial of Service due to signed integer overflow
CVE-2026-16529 PCP: PCP: Denial of Service due to signed integer overflow
Summary: A signed integer overflow in __pmGetPDU() (pdu.c:661) permanently corrupts
the process-wide static variable maxsize, rendering the affected daemon unable to read any
PDU for the remainder of its lifetime. No authentication or prior session state is required.
When php->len = 0x7FFFFFFF, the expression PDU_CHUNK * (1 + php->len / PDU_CHUNK)
overflows to -2147483648. Every subsequent call to __pmFindPDUBuf(maxsize) returns
NULL, causing silent connection failures. Two attack vectors were confirmed: pmlogger TCP
4330 (conditional on PMLOGGER_LOCAL being unset) and pmcd TCP 44321 during SASL
negotiation.
Prerequisites: Vector 1 (pmlogger TCP 4330): Default installation, no credentials required.
Bound to loopback
https://github.com/free5gc/free5gc/issues/906https://github.com/free5gc/free5gc/security/advisories/GHSA-44qj-cghf-9p97https://github.com/free5gc/smf/commit/e0974e07ddab44a67d36a563cca383b2449e33e5https://github.com/free5gc/smf/pull/203https://github.com/free5gc/free5gc/security/advisories/GHSA-44qj-cghf-9p97
2026-05-27
Published