Executive brief
Ella Core is a 5G core platform used to manage private cellular networks. A vulnerability in how the system handles specific handover failure messages allows an attacker to crash the core service. This results in a total loss of connectivity for all mobile subscribers on the affected private network until the service is restored.
Technical details
A NULL pointer dereference (CWE-476) exists in the NGAP handover handlers of Ella Core. The vulnerability is triggered when the core processes a malformed or specific NGAP handover failure message sent from a gNodeB (base station). An attacker with sufficient privileges to control or influence a gNodeB can send these messages to cause a process panic (crash). This results in a complete denial of service for the 5G core and its connected User Equipment (UE). The issue is fixed in version 1.8.0 by improving guards and validation within the NGAP handover handlers.
Affected products
- Ella Networks Ella Core < 1.8.0
Timeline
- 2026-03-30: patched: Version 1.8.0 released
- 2026-03-30: advisory: GitHub Security Advisory GHSA-6gm8-3g4h-w82m published
- 2026-04-02: disclosed: CVE-2026-34761 published