Junglewise Threat Intelligence

CVE-2026-42082: free5GC AMF improper security check in concurrent procedures

CVE-2026-42082 · Severity: low · CVSS 3.7 · Published 2026-05-27

Technologies: github.com/free5gc/amf (Go). Vendors: Go, free5GC.

Executive brief

A vulnerability exists in the Free5GC Access and Mobility Management Function (AMF), which manages mobile device connections in a 5G network. The system fails to properly coordinate security updates and network handovers when they happen at the same time. This can cause a mismatch in security keys between the mobile device and the network, potentially leading to dropped connections or failed handovers.

Technical details

The Free5GC AMF implementation of the Access and Mobility Management Function (AMF) violates 3GPP TS 33.501 §6.9.5.1 by failing to implement cross-procedure validation between NAS Security Mode Command (SMC) and N2 handover procedures. Specifically, the 'SecurityMode()' function in 'internal/gmm/sm.go' initiates an SMC without checking for ongoing N2 handovers, and 'handleHandoverRequiredMain()' in 'internal/ngap/handler.go' initiates handovers without checking for ongoing SMCs. Because SMC activates a new KAMF key while N2 handovers rely on NH/NCC derived from the previous key, concurrent execution causes the target gNB and the User Equipment (UE) to derive different KgNB keys. This results in an Access Stratum (AS) security context mismatch, impacting connection integrity and availability.

Affected products

  • Free5GC AMF <= 1.4.3

Timeline

  • 2026-05-07: advisory: GitHub Advisory GHSA-vrrx-58h3-prmh published
  • 2026-05-27: disclosed: NVD publication date

References

Related threats