CVE-2026-8783

MEDIUM

omec-project amf dispatcher.go UERadioCapabilityCheckResponse null pointer dereference

Title source: cna
STIX 2.1

Description

A security vulnerability has been detected in omec-project amf up to 2.1.3-dev. This impacts the function UERadioCapabilityCheckResponse of the file ngap/dispatcher.go. Such manipulation leads to null pointer dereference. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.2.0 will fix this issue. Upgrading the affected component is advised. The same pull request fixes multiple security issues.

References (7)

Core 7
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-364407 | omec-project amf dispatcher.go UERadioCapabilityCheckResponse null pointer dereference
https://vuldb.com/vuln/364407
Signature, Permissions Required signature permissions-required
VDB-364407 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/364407/cti
Third Party Advisory third-party-advisory
Submit #811655 | Linux Foundation Projects SD-Core 2.1.1 Memory Corruption
https://vuldb.com/submit/811655
Exploit exploit issue-tracking
https://github.com/omec-project/amf/issues/675

Scores

CVSS v3 4.3
EPSS 0.0040
EPSS Percentile 31.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-404 CWE-476
Status published
Products (3)
omec-project/amf 0 - 2.2.0Go
omec-project/amf 2.1.3-dev
omec-project/amf 2.2.0
Published May 18, 2026
Tracked Since May 18, 2026