CVE 6.9 MEDIUM

Free5GC pcf smpolicy.go HandleCreateSmPolicyRequest null pointer dereference_CVE-2026-1739

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability has been found in Free5GC pcf up to 1.4.1. This affects the function HandleCreateSmPolicyRequest of the file internal/sbi/processor/smpolicy.go. The manipulation leads to null pointer dereference. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is df535f5524314620715e842baf9723efbeb481a7. Applying a patch is the recommended action to fix this issue.

Basic Information

ID CVE-2026-1739
Source VulDB
Published Feb 2, 2026 at 02:02

Affected Product

Vendor Free5GC
Product pcf
Version 1.4.0
Affected Versions Free5GC pcf 1.4.0
Free5GC pcf 1.4.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.