Description
A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_handlers.c of the component NGSetup Handler. Executing a manipulation can lead to state issue. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-08-30
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates from a state consistency error in the ngap_amf_handlers.c file of the NGSetup handler. This flaw allows an attacker to manipulate protocol messages and cause the system to enter an inconsistent internal state, potentially leading to misbehavior or denial of service. The weakness is categorized as CWE‑371, indicating improper state validation.

Affected Systems

The affected product is Linux Foundation Magma, specifically version 1.9.0. The issue is located in the NGSetup component; no additional affected versions have been identified.

Risk and Exploitability

The CVSS score of 6.9 reflects a moderate severity, and the vulnerability is exploitable remotely, as publicly available exploits have been released. Because EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, the exploit demand is unclear, but the remote nature increases the risk. An attacker could manipulate NGAP messages to disrupt service or corrupt state.

Generated by OpenCVE AI on August 30, 2026 at 17:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Magma to a patched version (1.9.x or later) as soon as it is available.
  • If an upgrade cannot be performed immediately, restrict or disable the NGSetup NGAP handler endpoints to trusted networks only.
  • Continuously monitor system logs and network traffic for signs of state corruption or abnormal NGAP activity.

Generated by OpenCVE AI on August 30, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 30 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_handlers.c of the component NGSetup Handler. Executing a manipulation can lead to state issue. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Title Linux Foundation Magma NGSetup ngap_amf_handlers.c state issue
First Time appeared Linux Foundation
Linux Foundation magma
Weaknesses CWE-371
CPEs cpe:2.3:o:linux_foundation:magma:*:*:*:*:*:*:*:*
Vendors & Products Linux Foundation
Linux Foundation magma
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Linux Foundation Magma
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-30T16:30:08.876Z

Reserved: 2026-08-29T18:44:11.989Z

Link: CVE-2026-82551

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-30T17:16:38.687

Modified: 2026-08-30T17:16:38.687

Link: CVE-2026-82551

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T17:30:17Z

Weaknesses