Executive brief
A vulnerability in the Free5GC Access and Mobility Management Function (AMF) allows a compromised or untrusted base station to disrupt mobile service for specific users. By sending a specially crafted network request, an attacker can corrupt the security settings stored for a mobile device, causing all future connection handovers to fail. This results in a persistent loss of cellular connectivity for the affected user until they manually re-register with the network.
Technical details
The Access and Mobility Management Function (AMF) in Free5GC (v1.4.3 and earlier) fails to implement the verification requirements of 3GPP TS 33.501 §6.7.3.1. Specifically, the 'handlePathSwitchRequestMain' function in 'amf/internal/ngap/handler.go' unconditionally overwrites locally stored User Equipment (UE) Security Capabilities with values provided in an NGAP PathSwitchRequest message from a gNB. An attacker controlling a gNB can send a PathSwitchRequest with null or unsupported integrity/encryption algorithms. The AMF then propagates these corrupted capabilities to target gNBs in subsequent Handover Request messages, leading to mandatory handover rejections per TS 38.413 and resulting in a persistent DoS for the affected UE.
Affected products
- free5gc amf <= 1.4.3
Timeline
- 2026-05-07: advisory: GitHub Advisory GHSA-77x9-rf64-92gv published
- 2026-05-27: disclosed: NVD publication of CVE-2026-42081