OMEC Project AMF Null Pointer Dereference Vulnerability in UERadioCapabilityCheckResponse Handler

Vulnerability

A null pointer dereference vulnerability has been identified in the OMEC Project AMF component, affecting versions through 2.1.3-dev. The issue arises in the NGAP message handling, specifically within the UERadioCapabilityCheckResponse function, located in the ngap/dispatcher.go file. This vulnerability can be exploited remotely, leading to a crash of the AMF process.

Impact

Exploitation of this vulnerability causes a segmentation fault, crashing the AMF process.

Reproduction

The vulnerability can be reproduced by sending a malformed UERadioCapabilityCheckResponse NGAP message. This message should be crafted to include per data that is out of range, which will trigger the null pointer dereference when the AMF attempts to process the message.

Remediation

Users are advised to upgrade to OMEC Project AMF version 2.2.0 or later, where this vulnerability has been fixed.

Added: May 18, 2026, 4:20 AM
Updated: May 18, 2026, 4:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
8.7
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.