在 Linux Foundation 的 Magma 1.9.0 中发现了一个安全缺陷。该缺陷影响了 NGSetupRequest 处理组件中的某个未知函数。对参数 NG-IoT-DefaultPagingDRX 进行操作会导致输入验证不当。该漏洞可被远程利用。相关漏洞利用代码已公开,可能被用于发起攻击。项目方已通过问题报告在较早阶段获知该问题,但尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Linux Foundation | Magma | 1.9.0 |
cpe:2.3:o:linux_foundation:magma:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82549 | 8.3 HIGH | Linux Foundation Magma SecurityModeComplete integrity check |
| CVE-2026-82547 | 6.5 MEDIUM | Linux Foundation Magma Registration Complete Message amf_fsm.cpp improper authentication |
| CVE-2026-82548 | 5.3 MEDIUM | Linux Foundation Magma InitialUEMessage information disclosure |
| CVE-2026-82551 | 5.3 MEDIUM | Linux Foundation Magma NGSetup ngap_amf_handlers.c state issue |
| CVE-2026-82552 | 4.3 MEDIUM | Linux Foundation Magma gNB Termination ngap_amf.c denial of service |
No comments yet