A vulnerability labeled as problematic has been found in omec-project amf up to 2.1.3-dev. Impacted is the function NGSetupRequest of the file ngap/handler.go. Executing a manipulation of the argument InformationElement can lead to memory corruption.

This vulnerability is tracked as CVE-2026-8779. The attack can be launched remotely. Moreover, an exploit is present.

The affected component should be upgraded.

The same pull request fixes multiple security issues.