Junglewise Threat Intelligence

CVE-2026-82550: Linux Foundation Magma NGSetupRequest improper input validation

CVE-2026-82550 · Severity: medium · CVSS 5.3 · Published 2026-08-30

Technologies: Linux Foundation Magma. Vendors: Linux Foundation.

Executive brief

Magma is an open-source platform used by telecom operators to manage mobile networks and provide connectivity services. A flaw in the AMF (Access Management Function) component causes it to reject valid network setup requests containing certain optional parameters, resulting in denial of service and potential interoperability issues when communicating with compliant base stations.

Technical details

The vulnerability is an improper input validation flaw in the NGSetupRequest handler of Magma's AMF component. When processing an NGAP (NG Application Protocol) message with the NG-IoT-DefaultPagingDRX parameter set, the AMF decoder throws an error instead of ignoring the optional field as per specification. This occurs even though the parameter has its Criticality flag set to "ignore," meaning compliant implementations should proceed without error. An attacker or non-compliant gNB can trigger this decoder error remotely via crafted SCTP-transported NGAP messages, causing the AMF to reject legitimate setup requests and disrupting network connectivity.

Affected products

  • Linux Foundation Magma 1.9.0

Timeline

  • 2026-07-15: disclosed
  • 2026-08-30: advisory

References

Related threats