CVE-2022-43677: Medium severity free5gc Free5gc vulnerability
Published Oct 24, 2022
·Updated
In free5GC 3.2.1, a malformed NGAP message can crash the AMF and NGAP decoders via an index-out-of-range panic in aper.GetBitString.
Other sources
In free5GC 3.2.1, a malformed NGAP message can crash the AMF and NGAP decoders via an index-out-of-range panic in aper.GetBitString.
Affected Software
2 affected components
go/github.com/free5gc/free5gc<=3.2.1
free5gc Free5gc=3.2.1
Event History
Oct 24, 2022
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Advisory Published
via GitHub·07:00 PM
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-43677.
2
What is the severity of CVE-2022-43677?
The severity of CVE-2022-43677 is medium.
3
Which version of free5GC is affected by CVE-2022-43677?
CVE-2022-43677 affects version 3.2.1 of free5GC.
4
How can a malformed NGAP message crash the AMF and NGAP decoders?
A malformed NGAP message can crash the AMF and NGAP decoders by triggering an index-out-of-range panic in aper.GetBitString.
5
Is there a reference available for CVE-2022-43677?
Yes, you can refer to the following link for more information: [Github Issue #402](https://github.com/free5gc/free5gc/issues/402)