[GHSA-q7c8-gfjh-8v4p] An issue was discovered in Free5gc NRF 1.4.0. In the...#7606
Open
p0sql wants to merge 1 commit intop0sql/advisory-improvement-7606from
Open
[GHSA-q7c8-gfjh-8v4p] An issue was discovered in Free5gc NRF 1.4.0. In the...#7606p0sql wants to merge 1 commit intop0sql/advisory-improvement-7606from
p0sql wants to merge 1 commit intop0sql/advisory-improvement-7606from
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates
Comments
Hello,
I would like to request a review of the GitHub Security Advisory GHSA-q7c8-gfjh-8v4p (CVE-2025-66719).
The advisory currently references issue #736 (opened Nov 17), but the same vulnerability appears to have been originally reported in issue #733 (opened Nov 6).
Could you please review the attribution and consider adding the original report (#733) to the advisory references/credits to ensure the correct disclosure timeline is reflected?
The vulnerability was discovered with py5sig, a tool developed by French National Cybersecurity Agency - ANSSI (https://github.com/ANSSI-FR/py5sig)
Thank you.