free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's BSF PUT /nbsf-management/v1/subscriptions/{subId} handler has an unsynchronized write on the global Subscriptions map. The handler first reads the map under RLock() via BSFContext.GetSubscription(subId), but if the subscription does not exist, ReplaceIndividualSubcription() writes back to the same map directly without taking the mutex (bsfContext.BsfSelf.Subscriptions[subId] = subscription). Under concurrent authenticated PUT load, one goroutine can read while another writes the map, which causes the Go runtime to abort the process with fatal error: concurrent map read and map write (Go runtime panics that come from concurrent map access bypass recover() and terminate the process). The BSF container exits with code 2 -- the entire BSF SBI surface goes down until restart. This vulnerability is fixed in 4.2.2.
References
| Link | Resource |
|---|---|
| https://github.com/free5gc/bsf/commit/277908565fd628d974a13ef562b81a8b7b519ffa | Patch |
| https://github.com/free5gc/bsf/pull/7 | Issue Tracking Patch |
| https://github.com/free5gc/free5gc/issues/926 | Exploit Issue Tracking |
| https://github.com/free5gc/free5gc/security/advisories/GHSA-27ph-8q4f-h7m7 | Exploit Vendor Advisory |
| https://github.com/free5gc/free5gc/issues/926 | Exploit Issue Tracking |
| https://github.com/free5gc/free5gc/security/advisories/GHSA-27ph-8q4f-h7m7 | Exploit Vendor Advisory |
Configurations
History
28 May 2026, 18:24
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Free5gc free5gc
Free5gc |
|
| CPE | cpe:2.3:a:free5gc:free5gc:*:*:*:*:*:*:*:* | |
| References | () https://github.com/free5gc/bsf/commit/277908565fd628d974a13ef562b81a8b7b519ffa - Patch | |
| References | () https://github.com/free5gc/bsf/pull/7 - Issue Tracking, Patch | |
| References | () https://github.com/free5gc/free5gc/issues/926 - Exploit, Issue Tracking | |
| References | () https://github.com/free5gc/free5gc/security/advisories/GHSA-27ph-8q4f-h7m7 - Exploit, Vendor Advisory |
27 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/free5gc/free5gc/issues/926 - | |
| References | () https://github.com/free5gc/free5gc/security/advisories/GHSA-27ph-8q4f-h7m7 - |
27 May 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-27 17:16
Updated : 2026-05-28 18:24
NVD link : CVE-2026-44318
Mitre link : CVE-2026-44318
CVE.ORG link : CVE-2026-44318
JSON object : View
Products Affected
free5gc
- free5gc
