Junglewise Threat Intelligence

CVE-2026-82552: Linux Foundation Magma gNB termination context cleanup denial of service

CVE-2026-82552 · Severity: medium · CVSS 4.3 · Published 2026-08-30

Technologies: Linux Foundation Magma. Vendors: Linux Foundation.

Executive brief

Magma is an open-source platform used to build, operate, and manage mobile networks and 5G infrastructure. This vulnerability allows remote attackers to cause denial of service by preventing mobile user equipment from registering on the network when a base station (gNB) terminates abnormally, due to failure to clean up session context data. An attacker could trigger repeated gNB disconnections to permanently block legitimate users from accessing the network until the system is manually restarted.

Technical details

The vulnerability is a context cleanup failure in the gNB Termination Handler component (ngap_amf.c). When a gNB disconnects or restarts, the AMF (Access and Mobility Management Function) fails to properly clear session contexts and RAN_UE_NGAP_ID identifiers from memory. This causes subsequent registration attempts with the same identifiers to fail with duplicate context errors, permanently blocking those identifiers until AMF restart. The vulnerability is network-reachable and requires no authentication; an attacker with network access to the gNB can trigger the condition by causing a gNB restart or disconnection. The fix requires proper context cleanup on gNB termination in the affected code paths (ngap_amf.c, ngap_amf_nas_procedure.c, and related handlers).

Affected products

  • Linux Foundation Magma 1.9.0

Timeline

  • 2026-07-15: disclosed: Issue reported on GitHub
  • 2026-08-30: advisory: CVE-2026-82552 published

References

Related threats