CVE-2026-82550
Received Received - Intake

Improper Input Validation in Linux Foundation Magma 1.9.0

Vulnerability report for CVE-2026-82550, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-30

Last updated on: 2026-08-30

Assigner: VulDB

Description

A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetupRequest Handler. Performing a manipulation of the argument NG-IoT-DefaultPagingDRX results in improper input validation. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-30
Last Modified
2026-08-30
Generated
2026-08-30
AI Q&A
2026-08-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux_foundation magma 1.9.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Linux Foundation Magma 1.9.0 where the NGSetupRequest Handler improperly validates the NG-IoT-DefaultPagingDRX argument. A remote attacker can manipulate this input to cause improper input validation, leading to potential denial of service or interoperability issues with standards-compliant 5G equipment.

Detection Guidance

To detect this vulnerability, monitor for NGSetupRequest messages containing the NG-IoT-DefaultPagingDRX information element that trigger decoder errors in the AMF component of Magma. Check logs for SCTP traffic to Magma Core instances with 5G support for these specific NGAP messages.

Impact Analysis

This flaw may allow remote attackers to disrupt services by causing denial of service when a valid 5G message is incorrectly rejected. It could also affect interoperability between Magma and other 5G network components, potentially leading to network outages or degraded performance.

Compliance Impact

The vulnerability involves improper input validation in the NGSetupRequest handler of Linux Foundation Magma 1.9.0, leading to potential denial of service due to incorrect rejection of standards-compliant messages. This could impact compliance with regulations requiring reliable network operations, such as HIPAA's availability requirements or GDPR's data processing integrity principles, by disrupting service continuity.

Mitigation Strategies

Apply patches or updates from the Magma project if available. If no patch exists, consider disabling the NG-IoT-DefaultPagingDRX field handling in AMF or filter out non-compliant NGSetupRequest messages at the network perimeter.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82550. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart