First published: Mon Oct 24 2022(Updated: )
In free5GC 3.2.1, a malformed NGAP message can crash the AMF and NGAP decoders via an index-out-of-range panic in `aper.GetBitString`.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Free5gc Free5gc | =3.2.1 | |
go/github.com/free5gc/free5gc | <=3.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-43677.
The severity of CVE-2022-43677 is medium.
CVE-2022-43677 affects version 3.2.1 of free5GC.
A malformed NGAP message can crash the AMF and NGAP decoders by triggering an index-out-of-range panic in aper.GetBitString.
Yes, you can refer to the following link for more information: [Github Issue #402](https://github.com/free5gc/free5gc/issues/402)