CVE-2026-82551
Received Received - Intake

State Issue in Linux Foundation Magma NGSetup Handler

Vulnerability report for CVE-2026-82551, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-30

Last updated on: 2026-08-30

Assigner: VulDB

Description

A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_handlers.c of the component NGSetup Handler. Executing a manipulation can lead to state issue. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-30
Last Modified
2026-08-30
Generated
2026-08-30
AI Q&A
2026-08-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux_foundation magma 1.9.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-371

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Linux Foundation Magma 1.9.0 where the Access and Mobility Management Function (AMF) incorrectly accepts NGAP messages without completing the NGSetup process. Attackers can send arbitrary messages after establishing an SCTP channel, potentially leading to unauthorized UE registration or spoofing attacks.

Detection Guidance

Monitor for NGAP messages sent before NGSetupRequest completion. Check logs for InitialUEMessage or other NGAP messages without prior NGSetupRequest. Inspect AMF subcomponent logs in Docker-based deployments for unexpected message sequences.

Impact Analysis

It may allow remote attackers to manipulate the system, leading to unauthorized user equipment registration, spoofing attacks, or disclosure of user equipment context information. The AMF cannot properly determine gNB capabilities without NGSetup, affecting network security.

Compliance Impact

This vulnerability could potentially lead to unauthorized user equipment registration and disclosure of user context information, which may violate data protection requirements under GDPR and HIPAA. Unauthorized access risks exposing personal data, triggering compliance breaches for handling sensitive information.

Mitigation Strategies

Ensure NGSetupRequest is enforced as the first message after SCTP channel establishment. Update Magma to a patched version. Filter NGAP messages at the network level to block non-NGSetupRequest messages until NGSetup completes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82551. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart