<Vulnerability name="CVE-2026-9298">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-05-23T10:30:13</PublicDate>
    <Bugzilla id="2480897" url="https://bugzilla.redhat.com/show_bug.cgi?id=2480897" xml:lang="en:us">
AMF: omec-project amf: Memory corruption vulnerability in PathSwitchRequest Handler
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>6.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-787</CWE>
    <Details xml:lang="en:us" source="Mitre">
A vulnerability was detected in omec-project amf up to 2.1.1. Affected by this vulnerability is an unknown functionality of the component PathSwitchRequest Handler. The manipulation results in memory corruption. The attack may be launched remotely. The exploit is now public and may be used. It is advisable to implement a patch to correct this issue.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in omec-project amf. A remote attacker could exploit an unknown functionality within the PathSwitchRequest Handler component, leading to memory corruption.
    </Details>
    <PackageState cpe="cpe:/a:redhat:enterprise_linux_ai:3">
        <ProductName>Red Hat Enterprise Linux AI (RHEL AI) 3</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>AMF</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-9298
https://nvd.nist.gov/vuln/detail/CVE-2026-9298
https://github.com/omec-project/amf/
https://github.com/omec-project/amf/issues/680
https://github.com/omec-project/amf/pull/666
https://vuldb.com/submit/811684
https://vuldb.com/vuln/365245
https://vuldb.com/vuln/365245/cti
    </References>
</Vulnerability>