Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: python312Packages.pysmf

Found 6 matching suggestions

View:
Compact
Detailed
created 3 weeks, 2 days ago
free5GC SMF crash (nil pointer dereference) on PFCP SessionReportRequest when ReportType.DLDR is set but DownlinkDataReport IE is missing

free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, SMF panics due to nil pointer dereference and the SMF process terminates. This is triggered by a malformed PFCP SessionReportRequest on the SMF PFCP (UDP/8805) interface. No known upstream fix is available, but some workarounds are available. ACL/firewall the PFCP interface so only trusted UPF IPs can reach SMF (reduce spoofing/abuse surface); drop/inspect malformed PFCP SessionReportRequest messages at the network edge where feasible, and/or add recover() around PFCP handler dispatch to avoid whole-process termination (mitigation only).

Affected products

smf
  • ==<= 1.4.1

Matching in nixpkgs

pkgs.libsmf

C library for reading and writing Standard MIDI Files

Package maintainers

created 1 month ago
File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin …

File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.

Affected products

SMF
  • ==<= 2.0.3

Matching in nixpkgs

pkgs.libsmf

C library for reading and writing Standard MIDI Files

Package maintainers

created 1 month ago
There is a file disclosure vulnerability in SMF (Simple Machines …

There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not trusted beyond the SMF deployment. This vulnerability allows them to read arbitrary files on the filesystem and therefore gain new privileges by reading the settings.php with the database passwords.

Affected products

SMF
  • ==through 2.0.3

Matching in nixpkgs

pkgs.libsmf

C library for reading and writing Standard MIDI Files

Package maintainers

Permalink CVE-2026-1683
5.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
created 1 month, 3 weeks ago
Free5GC SMF PFCP handler.go HandlePfcpSessionReportRequest denial of service

A vulnerability has been found in Free5GC SMF up to 4.1.0. Affected by this vulnerability is the function HandlePfcpSessionReportRequest of the file internal/pfcp/handler/handler.go of the component PFCP. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. To fix this issue, it is recommended to deploy a patch.

Affected products

SMF
  • ==4.1.0
  • ==4.0

Matching in nixpkgs

pkgs.smfh

Sleek Manifest File Handler

pkgs.libsmf

C library for reading and writing Standard MIDI Files

Package maintainers

Permalink CVE-2026-1682
5.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
created 1 month, 3 weeks ago
Free5GC SMF PFCP UDP Endpoint handler.go HandlePfcpAssociationReleaseRequest null pointer dereference

A flaw has been found in Free5GC SMF up to 4.1.0. Affected is the function HandlePfcpAssociationReleaseRequest of the file internal/pfcp/handler/handler.go of the component PFCP UDP Endpoint. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The exploit has been published and may be used. A patch should be applied to remediate this issue.

Affected products

SMF
  • ==4.1.0
  • ==4.0

Matching in nixpkgs

pkgs.smfh

Sleek Manifest File Handler

pkgs.libsmf

C library for reading and writing Standard MIDI Files

Package maintainers

Permalink CVE-2026-1684
5.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
created 1 month, 3 weeks ago
Free5GC SMF PFCP UDP Endpoint pfcp_reports.go HandleReports denial of service

A vulnerability was found in Free5GC SMF up to 4.1.0. Affected by this issue is the function HandleReports of the file /internal/context/pfcp_reports.go of the component PFCP UDP Endpoint. The manipulation results in denial of service. The attack can be executed remotely. It is advisable to implement a patch to correct this issue.

Affected products

SMF
  • ==4.1.0
  • ==4.0

Matching in nixpkgs

pkgs.smfh

Sleek Manifest File Handler

pkgs.libsmf

C library for reading and writing Standard MIDI Files

Package maintainers