Description
A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown functionality of the file tasks/ngap/ngap_amf.c of the component gNB Termination Handler. The manipulation leads to denial of service. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Published: 2026-08-30
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the gNB Termination Handler of Linux Foundation Magma 1.9.0, specifically the ngap_amf.c file. An unknown functionality in that file can be manipulated to trigger a denial of service. The exploitation can be performed remotely, and a public exploit has been disclosed, making it a real threat to 5G network availability.

Affected Systems

The affected product is Linux Foundation Magma version 1.9.0. The flaw is present in the gNB Termination handler component, particularly the tasks/ngap/ngap_amf.c file. No other Magma releases have been confirmed as affected according to the current data.

Risk and Exploitability

The CVSS score of 5.3 places the vulnerability in the moderate category. EPSS is not available, so the likelihood of exploitation remains uncertain, but the fact that an exploit is publicly disclosed and can be carried out remotely indicates that attacks are plausible. The vulnerability is not listed in CISA’s KEV catalog, but a remote denial of service could still disrupt 5G network services. No privileged access is required; a remote attacker can attack by sending crafted requests to the vulnerable endpoint.

Generated by OpenCVE AI on August 30, 2026 at 18:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any official Magma patch or upgrade to a newer release that includes fixes for CVE‑2026‑82552.
  • If no patch is available, temporarily disable the gNB Termination Handler or restrict remote access to the ngap_amf.c functionality until a permanent fix is deployed.
  • Implement network filtering or firewall rules to block traffic patterns that trigger the malformed logic in ngap_amf.c, reducing the attack surface.
  • Continuously monitor system logs for abnormal activity or repeated failures originating from ngap_amf.c and configure alerts to detect potential exploitation attempts.

Generated by OpenCVE AI on August 30, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 30 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown functionality of the file tasks/ngap/ngap_amf.c of the component gNB Termination Handler. The manipulation leads to denial of service. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Title Linux Foundation Magma gNB Termination ngap_amf.c denial of service
First Time appeared Linux Foundation
Linux Foundation magma
Weaknesses CWE-404
CPEs cpe:2.3:o:linux_foundation:magma:*:*:*:*:*:*:*:*
Vendors & Products Linux Foundation
Linux Foundation magma
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Linux Foundation Magma
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-31T16:34:39.350Z

Reserved: 2026-08-29T18:44:16.070Z

Link: CVE-2026-82552

cve-icon Vulnrichment

Updated: 2026-08-31T16:34:33.745Z

cve-icon NVD

Status : Deferred

Published: 2026-08-30T17:16:39.370

Modified: 2026-09-01T20:48:22.513

Link: CVE-2026-82552

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T21:00:04Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release