PT-2026-25087 · Ella Core · Ella Core

P1-Aji

·

Published

2026-03-12

·

Updated

2026-03-25

·

CVE-2026-32319

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Ella Core versions prior to 1.5.1
Description Ella Core is a 5G core designed for private networks. Prior to version 1.5.1, the software experiences a panic when processing a malformed integrity-protected NGAP/NAS message with a length less than 7 bytes. An attacker capable of sending crafted NAS messages to Ella Core can cause the process to crash, resulting in service disruption for all connected subscribers. No authentication is required for exploitation. The issue involves processing messages via the InitialUEMessage and affects the AMF component. The vulnerability is related to insufficient length verification during NAS message handling.
Recommendations Update Ella Core to version 1.5.1 or later.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32319
GHSA-M9PM-W3GV-C68F
GO-2026-4692
SUSE-SU-2026:1042-1

Affected Products

Ella Core