A vulnerability labeled as problematic has been found in omec-project amf up to 2.1.3-dev. Impacted is the function
NGSetupRequest of the file ngap/handler.go. Executing a manipulation of the argument InformationElement can lead to memory corruption.
This vulnerability is tracked as CVE-2026-8779. The attack can be launched remotely. Moreover, an exploit is present.
The affected component should be upgraded.
The same pull request fixes multiple security issues.