Medium severity6.3NVD Advisory· Published May 23, 2026· Updated Jul 23, 2026
CVE-2026-9299
CVE-2026-9299
Description
A flaw has been found in omec-project amf up to 2.1.1. Affected by this issue is the function PDUSessionResourceModifyIndication of the file /go/src/amf/ngap/handler.go. This manipulation causes memory corruption. Remote exploitation of the attack is possible. The exploit has been published and may be used. Applying a patch is the recommended action to fix this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/omec-project/amfGo | < 1.7.1-0.20260421213846-34bc6724acc9 | 1.7.1-0.20260421213846-34bc6724acc9 |
Affected products
3- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-m9r6-r5c3-jw4jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-9299ghsaADVISORY
- github.com/omec-project/amf/commit/34bc6724acc97dba1f8691e586da95b042cb612dghsaWEB
- github.com/omec-project/amf/issues/681nvdWEB
- github.com/omec-project/amf/pull/666nvdWEB
- vuldb.com/submit/811829nvdWEB
- vuldb.com/vuln/365246nvdWEB
- vuldb.com/vuln/365246/ctinvdWEB
News mentions
1- Free5GC AMF: Four Memory Corruption CVEs Disclosed in NGAP HandlersVypr Intelligence · May 23, 2026