VDB
KO
MEDIUM 6.3

GHSA-m9r6-r5c3-jw4j

omec-project amf Vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer

Details

A flaw has been found in omec-project amf up to 2.1.1. Affected by this issue is the function PDUSessionResourceModifyIndication of the file /go/src/amf/ngap/handler.go. This manipulation causes memory corruption. Remote exploitation of the attack is possible. The exploit has been published and may be used. Applying a patch is the recommended action to fix this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/omec-project/amf
Introduced in: 0 Fixed in: 1.7.1-0.20260421213846-34bc6724acc9
Fix go get github.com/omec-project/amf@v1.7.1-0.20260421213846-34bc6724acc9

References