MEDIUM🇬🇧 English

CVE-2026-44318

CVSS 6.5v3.1pub. 2026-05-27upd. 2026-05-28

free5GC to open-source'owa implementacja 5G core network. W wersji przed 4.2.2 handler BSF PUT /nbsf-management/v1/subscriptions/{subId} ma niesynchronizowany zapis na globalnej mapie Subscriptions. Handler najpierw czyta mapę pod RLock() przez BSFContext.GetSubscription(subId), ale jeśli subskrypcja nie istnieje, ReplaceIndividualSubcription() pisze do tej samej mapy bezpośrednio bez zdobycia mutex (bsfContext.BsfSelf.Subscriptions[subId] = subscription). Pod równoczesnym obciążeniem PUT z autentykacją jeden goroutine może czytać podczas gdy inny pisze mapę, co powoduje że Go runtime przerywa proces z fatal error: concurrent map read and map write. Kontener BSF kończy pracę z kodem 2 — całe BSF SBI surface pada do ponownego uruchomienia. Podatność została naprawiona w wersji 4.2.2.

Pokaż oryginał (EN)

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's BSF PUT /nbsf-management/v1/subscriptions/{subId} handler has an unsynchronized write on the global Subscriptions map. The handler first reads the map under RLock() via BSFContext.GetSubscription(subId), but if the subscription does not exist, ReplaceIndividualSubcription() writes back to the same map directly without taking the mutex (bsfContext.BsfSelf.Subscriptions[subId] = subscription). Under concurrent authenticated PUT load, one goroutine can read while another writes the map, which causes the Go runtime to abort the process with fatal error: concurrent map read and map write (Go runtime panics that come from concurrent map access bypass recover() and terminate the process). The BSF container exits with code 2 -- the entire BSF SBI surface goes down until restart. This vulnerability is fixed in 4.2.2.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  • Free5gc

    APP
    Free5Gc
    < 4.2.2
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Container
CWE
Referencje

Powiązane podatności

CVE-2026-44329CRITICAL10.0PL ✓ten sam produkt

free5GC SMF: brak autoryzacji OAuth2 na endpointach UPI — pełny dostęp bez uwierzytelnienia

CVE-2026-44327CRITICAL10.0PL ✓ten sam produkt

Brak autoryzacji OAuth2 w grupie tras OAM w free5GC NEF (5G core)

CVE-2026-44326CRITICAL9.4PL ✓ten sam produkt

Brak autoryzacji OAuth2 w API NEF systemu free5GC (5G core)

CVE-2026-44315CRITICAL9.4PL ✓ten sam produkt

Brak autoryzacji OAuth2 w NEF API sieci 5G (free5GC)

CVE-2026-44330CRITICAL10.0PL ✓ten sam produkt

free5GC NEF: brak autoryzacji OAuth2 na trasach nnef-pfdmanagement