A malformed message can crash the free5gc/amf and free5gc/ngap decoders via an index-out-of-range panic in aper.GetBitString.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2022-1083" }
{ "imports": [ { "path": "github.com/free5gc/aper", "symbols": [ "GetBitString", "GetBitsValue", "Marshal", "MarshalWithParams", "Unmarshal", "UnmarshalWithParams" ] } ] }