CVE-2025-14953
Severity CVSS v4.0:
LOW
Type:
CWE-404
Improper Resource Shutdown or Release
Publication date:
19/12/2025
Last modified:
19/12/2025
Description
A flaw has been found in Open5GS up to 2.7.5. This impacts the function ogs_pfcp_handle_create_pdr in the library lib/pfcp/handler.c of the component FAR-ID Handler. Executing manipulation can lead to null pointer dereference. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is said to be difficult. The exploit has been published and may be used. This patch is called 93a9fd98a8baa94289be3b982028201de4534e32. It is advisable to implement a patch to correct this issue.
Impact
Base Score 4.0
2.30
Severity 4.0
LOW
Base Score 3.x
3.10
Severity 3.x
LOW
Base Score 2.0
2.10
Severity 2.0
LOW
References to Advisories, Solutions, and Tools
- https://github.com/open5gs/open5gs/commit/93a9fd98a8baa94289be3b982028201de4534e32
- https://github.com/open5gs/open5gs/issues/4179
- https://github.com/open5gs/open5gs/issues/4179#issue-3666399406
- https://github.com/open5gs/open5gs/issues/4179#issuecomment-3614868758
- https://vuldb.com/?ctiid_337589=
- https://vuldb.com/?id_337589=
- https://vuldb.com/?submit_716799=



