CVE-2026-94043 Details
Description
A vulnerability was determined in Free5GC up to 4.2.3. This vulnerability affects unknown code of the file /corefuzzer_deps/free5gc/NFs/amf/internal/gmm/handler.go of the component Gmm Handler. This manipulation causes race condition. The attack can be initiated remotely. Patch name: e323b01464355781b8b8d5dd695e05cbc00a62f2. To fix this issue, it is recommended to deploy a patch.
A race condition vulnerability has been identified in Free5GC versions through 4.2.3, specifically within the GMM handler component. The issue arises in the file 'handler.go', where unsynchronized access to the RAN UE context can lead to a crash. This vulnerability can be exploited remotely, causing the AMF process to terminate unexpectedly when concurrent 'RegistrationRequest' messages are processed over the same gNB SCTP connection, which is being closed simultaneously. This flaw creates a denial-of-service condition by disrupting normal operations.
Users are advised to update to Free5GC version 4.2.4, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 20, 2026CISA-ADP
Assessed Sep 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/free5gc/free5gc/issues/1109 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/submit/949261 | CISA-ADP | Issue TrackingPermission Required |
| https://github.com/free5gc/amf/commit/e323b01464355781b8b8d5dd695e05cbc00a62f2 | [email protected] | Source CodeVendor |
| https://github.com/free5gc/amf/pull/238 | [email protected] | Issue TrackingVendor |
| https://github.com/free5gc/free5gc/ | [email protected] | ProductSource CodeVendor |
| https://github.com/free5gc/free5gc/issues/1109 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-94043 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/949261 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/407972 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/407972/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| free5GC AMF | <= 4.2.3 (semver) |
CPE
Remediation
| |
| free5GC | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 21, 2026 | CVE Modified | CISA-ADP |
| Sep 20, 2026 | New CVE Received | [email protected] |
Volerion