CVE-2025-65568 Details
Description
A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a PFCP Session Establishment Request that includes a CreateFAR with an empty or truncated IPv4 address field is not properly validated. During parsing, parseFAR() calls ip2int(), which performs an out-of-bounds read on the IPv4 address buffer and triggers an index-out-of-range panic. An attacker who can send PFCP Session Establishment Request messages to the UPF's N4/PFCP endpoint can exploit this issue to repeatedly crash the UPF and disrupt user-plane services.
A denial-of-service vulnerability has been identified in the OmeC Project UPF, specifically in the pfcpiface component, version upf-epc-pfcpiface:2.1.3-dev. The issue arises after a PFCP association when a PFCP Session Establishment Request is received with a CreateFAR that has an empty or truncated IPv4 address. This malformed request is not properly validated, leading to an out-of-bounds read during parsing. The vulnerability can be exploited by sending crafted PFCP Session Establishment Request messages to the UPF's N4/PFCP endpoint, causing the UPF to crash and disrupting user-plane services.
Users can update to the latest version of the OmeC Project UPF where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/omec-project/upf/issues/962 | CISA-ADP | ExploitIssue TrackingThird Party Advisory |
| https://github.com/omec-project/upf/issues/962 | [email protected] | ExploitIssue TrackingThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| opennetworking upf | 2.1.3 dev |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 7, 2026 | Initial Analysis | [email protected] |
| Dec 19, 2025 | CVE Modified | CISA-ADP |
| Dec 18, 2025 | New CVE Received | [email protected] |