2.1 LOW
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): None (N)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): Low (L)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Exploit Maturity (E): POC (P)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): None (N)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): Low (L)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse dismissed (not in Nixpkgs)
omec-project amf handler.go NGSetupRequest memory corruption
A vulnerability was determined in omec-project amf up to 2.1.3-dev. Impacted is the function NGSetupRequest of the file ngap/handler.go. Executing a manipulation of the argument InformationElement can lead to memory corruption. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.2.0 is recommended to address this issue. The affected component should be upgraded. The same pull request fixes multiple security issues.
References
-
VDB-364403 | omec-project amf handler.go NGSetupRequest memory corruption vdb-entrytechnical-description
-
-
Submit #811616 | Linux Foundation Projects SD-Core 2.1.1 Memory Corruption third-party-advisory
-
-
Affected products
- ==2.2.0
- ==2.1.3-dev
Matching in nixpkgs
pkgs.amf
AMD's closed source Advanced Media Framework (AMF) driver
-
nixos-unstable 1.4.34-1787253
- nixpkgs-unstable 1.4.34-1787253
- nixos-unstable-small 1.4.34-1787253
-
nixos-25.11 1.4.34-1787253
- nixos-25.11-small 1.4.34-1787253
- nixpkgs-25.11-darwin 1.4.34-1787253
pkgs.bamf
Application matching framework
pkgs.amfora
Fancy terminal browser for the Gemini protocol
pkgs.ramfetch
Tool which displays memory information
pkgs.cramfsswap
Swap endianess of a cram filesystem (cramfs)
pkgs.samfirm-js
Program for downloading Samsung firmware
-
nixos-unstable 0.3.0-unstable-2023-12-27
- nixpkgs-unstable 0.3.0-unstable-2023-12-27
- nixos-unstable-small 0.3.0-unstable-2023-12-27
-
nixos-25.11 0.3.0-unstable-2023-12-27
- nixos-25.11-small 0.3.0-unstable-2023-12-27
- nixpkgs-25.11-darwin 0.3.0-unstable-2023-12-27
pkgs.amf-headers
Headers for The Advanced Media Framework (AMF)
pkgs.cramfsprogs
Tools to create, check, and extract content of CramFs images
-
nixos-unstable 2.1-unstable-2025-01-27
- nixpkgs-unstable 2.1-unstable-2025-01-27
- nixos-unstable-small 2.1-unstable-2025-01-27
-
nixos-25.11 2.1-unstable-2025-01-27
- nixos-25.11-small 2.1-unstable-2025-01-27
- nixpkgs-25.11-darwin 2.1-unstable-2025-01-27
pkgs.ArchiSteamFarm
Application with primary purpose of idling Steam cards from multiple accounts simultaneously
pkgs.archisteamfarm
Application with primary purpose of idling Steam cards from multiple accounts simultaneously
pkgs.python312Packages.py3amf
Action Message Format (AMF) support for Python 3
-
nixos-25.11 py3amf-0.8.11
- nixos-25.11-small py3amf-0.8.11
- nixpkgs-25.11-darwin py3amf-0.8.11
pkgs.python313Packages.py3amf
Action Message Format (AMF) support for Python 3
-
nixos-unstable py3amf-0.8.11
- nixpkgs-unstable py3amf-0.8.11
- nixos-unstable-small py3amf-0.8.11
-
nixos-25.11 py3amf-0.8.11
- nixos-25.11-small py3amf-0.8.11
- nixpkgs-25.11-darwin py3amf-0.8.11
pkgs.python314Packages.py3amf
Action Message Format (AMF) support for Python 3
-
nixos-unstable py3amf-0.8.11
- nixpkgs-unstable py3amf-0.8.11
- nixos-unstable-small py3amf-0.8.11
pkgs.python312Packages.dissect-cramfs
Dissect module implementing a parser for the CRAMFS file system
pkgs.python313Packages.dissect-cramfs
Dissect module implementing a parser for the CRAMFS file system
pkgs.python314Packages.dissect-cramfs
Dissect module implementing a parser for the CRAMFS file system
Package maintainers
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
-
@jopejoe1 jopejoe1 <nixpkgs@missing.ninja>
-
@devusb Morgan Helton <mhelton@devusb.us>
-
@deifactor Ash Zahlen <ext0l@riseup.net>
-
@davidak David Kleuker <post@davidak.de>
-
@bobby285271 Bobby Rong <rjl931189261@126.com>
-
@Pamplemousse Xavier Maso <xav.maso@gmail.com>
-
@blitz Julian Stecklina <js@alien8.de>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@zhaofengli Zhaofeng Li <hello@zhaofeng.li>
-
@markbeep Mark <mrkswrn@gmail.com>
-
@ungeskriptet David Wronek <nix@david-w.eu>