CVE-2025-65563 Details
Description
A denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory NodeID Information Element, the association setup handler dereferences a nil pointer instead of validating the message, causing a panic and terminating the UPF process. An attacker who can send PFCP Association Setup Request messages to the UPF's N4/PFCP endpoint can exploit this issue to repeatedly crash the UPF and disrupt user-plane services.
A denial-of-service vulnerability has been identified in the OmeC Project UPF component, specifically in versions prior to and including upf-epc-pfcpiface:2.1.3-dev. The issue arises when the UPF receives a PFCP Association Setup Request that omits the mandatory NodeID Information Element. The association setup handler then dereferences a nil pointer, leading to a panic that terminates the UPF process. This vulnerability can be exploited by an attacker who can send PFCP Association Setup Request messages to the UPF's N4/PFCP endpoint, causing repeated crashes and disrupting user-plane services.
Users can update to UPF version 2.1.3-dev or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/omec-project/upf/issues/955 | CISA-ADP | ExploitIssue TrackingThird Party Advisory |
| https://github.com/omec-project/upf/issues/955 | [email protected] | ExploitIssue TrackingThird Party Advisory |
| https://github.com/omec-project/upf/pull/963 | [email protected] | Issue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| opennetworking upf | <= 2.1.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 7, 2026 | Initial Analysis | [email protected] |
| Dec 19, 2025 | CVE Modified | CISA-ADP |
| Dec 18, 2025 | New CVE Received | [email protected] |