THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-334q-h5g3-fpxv (high) — free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI

[GHSA] GHSA-334q-h5g3-fpxv (high) — free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI

medgithub_advisoriesPublished 2026-08-28

GHSA-334q-h5g3-fpxv Severity: high CVE: CVE-2026-55784

free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI

### Summary

The AUSF component of free5GC stores per-subscriber authentication state in a global `sync.Map` keyed only by SUPI. Every incoming authentication request creates a new `AusfUeContext` and stores it under that SUPI key without checkin

Indicators of compromise

Original source: https://github.com/advisories/GHSA-334q-h5g3-fpxv