CVE-2025-29632 Details
Description
Buffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP, security.go, handler_generated.go, handleInitialUEMessageMain, DecodePlainNasNoIntegrityCheck, GetSecurityHeaderType components
A buffer overflow vulnerability has been identified in Free5gc version 4.0.0 and prior, allowing remote attackers to cause a denial-of-service condition. The issue arises in the AMF component when processing the InitialUEMessage. The vulnerability occurs because the message handling does not properly validate the content of the nASPDU reference, leading to an empty byte array being passed to the nas_security.DecodePlainNasNoIntegrityCheck function. This empty value causes a failure when accessing the NAS message security header, resulting in an error and a crash of the AMF.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/free5gc/free5gc/issues/657 | [email protected] | ExploitIssue Tracking |
| https://github.com/OHnogood/CVE-2025-29632/ | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| free5gc free5gc | 4.0.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2025 | Initial Analysis | [email protected] |
| May 29, 2025 | New CVE Received | [email protected] |
| May 29, 2025 | CVE Modified | CISA-ADP |