Memory Corruption Vulnerability in omec-project AMF Functionality
CVE-2026-9299
Key Information:
- Vendor
Omec-project
- Status
- Vendor
- CVE Published:
- 23 May 2026
Badges
What is CVE-2026-9299?
A memory corruption vulnerability has been identified in the omec-project AMF, specifically within the PDUSessionResourceModifyIndication function located in the /go/src/amf/ngap/handler.go file. This flaw enables potential remote exploitation, allowing an attacker to manipulate the system's memory. Immediate patching is recommended to ensure protection against potential exploitation. The issue has been documented, and a patch is available for users to secure their environments.
Affected Version(s)
amf 2.1.0
amf 2.1.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
