PT-2025-17557 · Open5Gs · Open5Gs Upf

·

CVE-2025-29339

·

Published

2025-04-22

·

Updated

2025-04-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Open5GS UPF versions up to v2.7.2
Description The issue results in an assertion failure vulnerability in PFCP session parameter validation. When processing a PFCP Session Establishment Request with PDN Type = 0, the UPF fails to handle the invalid value, triggering a fatal assertion check and causing a daemon crash.
Recommendations For Open5GS UPF versions up to v2.7.2, update to a version later than v2.7.2 to resolve the issue. As a temporary workaround, consider restricting the PDN Type parameter in the PFCP Session Establishment Request to prevent the assertion failure.

Exploit

Fix

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-29339

Affected Products

Open5Gs Upf