MEDIUM 6.5 Go
Ella Core panics on invalid PDU Session IDs in NGAP messages
GHSA-q669-4gmv-g8mf · CVE-2026-33281 · GO-2026-4783
Published · Modified
Description
Summary
Ella Core panics when processing NGAP messages with invalid PDU Session IDs outside of 1-15.
Impact
An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required.
Fix
Added PDU Session ID validations during NGAP message handling.
Ready to move
Start Securing
Free, no credit card | First findings in minutes