Executive brief
FlexRIC is a software controller used in cellular networks to manage radio access functions. A security flaw in its isolation mechanism allows a malicious application connected to the controller to delete the subscriptions and configurations of other applications. This breaks the separation between different users or services sharing the same network infrastructure, potentially leading to service disruptions.
Technical details
An authorization bypass exists in FlexRIC v2.0.0 within the iApp's xApp isolation mechanism. The root cause is a logic error in the equality function `eq_xapp_ric_gen_id()` located in `src/ric/iApp/xapp_ric_id.c`, where the code compares `m0->xapp_id` against itself instead of the second argument `m1->xapp_id`. This effectively ignores the xApp identity during validation. A malicious xApp connected to the iApp SCTP port (36422) can exploit this by sending an `E42_RIC_SUBSCRIPTION_DELETE_REQUEST` with a target's `ric_gen_id`, allowing it to delete subscriptions belonging to other xApps. This vulnerability breaks multi-tenant isolation in deployments where multiple xApps share the same RIC. No upstream patch was available at the time of disclosure.
Affected products
- EURECOM FlexRIC v2.0.0 through at least commit 6a595d8b (2025-11-12)
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory