CVE-2026-8349 Details
Description
A flaw has been found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGAP Message Handler. Executing a manipulation can lead to memory corruption. The attack can be launched remotely. The exploit has been published and may be used. This patch is called 8a4c33cdda866094f1989bdeff6d8642fce8de8435f89defd66831c97715f5aa. It is best practice to apply a patch to resolve this issue.
A memory corruption vulnerability has been identified in the OMEC Project AMF component, specifically in versions through 2.1.1. The issue arises within the NGAP Message Handler, where improper handling of certain messages can lead to memory corruption. This vulnerability can be exploited remotely, causing the AMF process to crash. The problem has been acknowledged and fixed in the latest release, version 2.2.1.
Users are advised to update to OMEC Project AMF version 2.2.1, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 12, 2026CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/omec-project/amf/ | [email protected] | ProductSource CodeVendor |
| https://github.com/omec-project/amf/issues/672 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/omec-project/amf/pull/666 | [email protected] | Source CodeVendor |
| https://hub.docker.com/layers/omecproject/5gc-amf/rel-2.2.1/images/sha256-8a4c33cdda866094f1989bdeff6d8642fce8de8435f89defd66831c97715f5aa | [email protected] | ProductVendor |
| https://vuldb.com/submit/811475 | [email protected] | Permission Required |
| https://vuldb.com/vuln/362663 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/362663/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| omec-project amf | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | New CVE Received | [email protected] |
Volerion