CVE-2026-8779 Details
Description
A vulnerability was determined in omec-project amf up to 2.1.3-dev. Impacted is the function NGSetupRequest of the file ngap/handler.go. Executing a manipulation of the argument InformationElement can lead to memory corruption. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.2.0 is recommended to address this issue. The affected component should be upgraded. The same pull request fixes multiple security issues.
A memory corruption vulnerability has been identified in the OMEC Project AMF (Access and Mobility Management Function) control plane component of the 5G core network, specifically in versions through 2.1.3-dev. The issue arises in the NGSetupRequest function within the ngap/handler.go file. The vulnerability can be exploited remotely by manipulating the InformationElement argument, leading to memory corruption. This flaw has been publicly disclosed and exploited.
Users are advised to upgrade to AMF version 2.2.0 or later, as this issue has been fixed in version 2.2.1.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 18, 2026CISA-ADP
Assessed May 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/omec-project/amf/ | [email protected] | ProductVendor |
| https://github.com/omec-project/amf/issues/671 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/omec-project/amf/pull/666 | [email protected] | Source CodeVendor |
| https://github.com/omec-project/amf/releases/tag/v2.2.0 | [email protected] | Release NotesVendor |
| https://vuldb.com/submit/811616 | [email protected] | Permission Required |
| https://vuldb.com/vuln/364403 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/364403/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| omec-project amf | <= 2.1.3-dev (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 18, 2026 | New CVE Received | [email protected] |
Volerion