Impact
The vulnerability resides in the gNB Termination Handler of Linux Foundation Magma 1.9.0, specifically the ngap_amf.c file. An unknown functionality in that file can be manipulated to trigger a denial of service. The exploitation can be performed remotely, and a public exploit has been disclosed, making it a real threat to 5G network availability.
Affected Systems
The affected product is Linux Foundation Magma version 1.9.0. The flaw is present in the gNB Termination handler component, particularly the tasks/ngap/ngap_amf.c file. No other Magma releases have been confirmed as affected according to the current data.
Risk and Exploitability
The CVSS score of 5.3 places the vulnerability in the moderate category. EPSS is not available, so the likelihood of exploitation remains uncertain, but the fact that an exploit is publicly disclosed and can be carried out remotely indicates that attacks are plausible. The vulnerability is not listed in CISA’s KEV catalog, but a remote denial of service could still disrupt 5G network services. No privileged access is required; a remote attacker can attack by sending crafted requests to the vulnerable endpoint.
OpenCVE Enrichment