CVE-2022-43677: free5GC vulnerable to malformed NGAP message crashing the AMF and NGAP decoders
(updated )
In free5GC 3.2.1, a malformed NGAP message can crash the AMF and NGAP decoders via an index-out-of-range panic in aper.GetBitString.
References
Detect and mitigate CVE-2022-43677 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →