在 Free5GC 4.2.3 及更早版本中发现了一个漏洞。该漏洞影响了 Gmm Handler 组件中 /corefuzzer_deps/free5gc/NFs/amf/internal/gmm/handler.go 文件的未知代码。此漏洞会导致竞态条件(race condition)。攻击者可远程发起该攻击。修复补丁编号为:e323b01464355781b8b8d5dd695e05cbc00a62f2。建议部署该补丁以修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Free5GC | 4.2.0 |
cpe:2.3:a:free5gc:free5gc:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93962 | 8.3 HIGH | Kamailio CDP Diameter Receiver receiver.c shm_malloc heap-based overflow |
| CVE-2026-94004 | 7.3 HIGH | DedeCMS mytag_js.php code injection |
| CVE-2026-93960 | 4.3 MEDIUM | Pixelfed OAuth Scope ApiV1Controller.php instancePeers missing authentication |
| CVE-2026-94030 | 3.1 LOW | SerenityOS LibGfx BMPLoader.cpp decode_bmp_pixel_data integer overflow |
No comments yet