Executive brief
Linux Foundation Magma is an open-source platform used to manage mobile networks and cellular infrastructure. A vulnerability in its 5G Access Gateway component allows attackers to submit unencrypted security-sensitive information (such as device capabilities) within initial registration messages that should be protected by encryption. An attacker could exploit this to leak device capability information for fingerprinting or profiling purposes.
Technical details
The vulnerability is an information disclosure flaw in the InitialUEMessage handler of Magma's Access Gateway (AMF component). The root cause is that the AMF accepts non-cleartext Information Elements (IEs), specifically the Capability 5GMM IE, in the InitialUEMessage during 5G registration, violating 3GPP TS 24.501 security requirements which mandate that only cleartext IEs be accepted until a security context is established. An unauthenticated remote attacker can send a specially crafted InitialUEMessage containing sensitive device capability information in unencrypted form, causing the AMF to process it without rejection. This allows leakage of device capabilities that could be used for device fingerprinting or profiling attacks. A fix is expected in future Magma releases.
Affected products
- Linux Foundation Magma 1.9.0
Timeline
- 2026-07-15: disclosed: Issue #16022 reported on GitHub
- 2026-08-30: advisory: CVE-2026-82548 published