-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The stack trace shows a panic in ParseMultiIEs (ie.go:637) during HeartbeatRequest processing. The error 'slice bounds out of range [6:4]' indicates improper buffer slicing based on attacker-controlled length values. The HeartbeatRequest's UnmarshalBinary method (heartbeat-request.go:101) propagates untrusted input to ParseMultiIEs without sufficient validation. These functions form the critical path where malformed IE length handling leads to buffer overflow.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/free5gc/free5gc | go | <= 3.3.0 |
Ongoing coverage of React2Shell