Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 Go

Ella Core panics on malformed ULNASTransport Message without a Request Type

GHSA-3366-gw57-fcm5 · CVE-2026-33283 · GO-2026-4776

Published · Modified

Description

Summary

Ella Core panics when processing malformed UL NAS Transport NAS messages without a Request Type.

Impact

An attacker able to send crafted NAS messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required.

Fix

Add a guard when receiving an UL NAS Message without a Request Type given no SM Context.

Ready to move

Start Securing

Free, no credit card | First findings in minutes