Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Go

Ella Core panics on malformed NGAP Location Report

GHSA-826q-wrq4-p23x · CVE-2026-33282 · GO-2026-4780

Published · Modified

Description

Summary

Ella Core panics when processing a malformed NGAP LocationReport message with ue-presence-in-area-of-interest event type and omitting the optional UEPresenceInAreaOfInterestList IE.

Impact

An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required.

Fix

Added IE presence verification to NGAP message handling.

Ready to move

Start Securing

Free, no credit card | First findings in minutes