PT-2026-28563 · Ella Core · Ella Core

CVE-2026-33904

·

Publicado

2026-03-26

·

Atualizado

2026-07-30

CVSS v3.1

6.5

Média

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Ella Core versions prior to 1.7.0
Description A deadlock in the AMF's SCTP notification handler can cause the entire AMF control plane to hang until the process is restarted. An attacker with access to the N2 interface can cause Ella Core to hang, resulting in a denial of service for all subscribers. The issue relates to the handling of SCTP notifications and the presence of stale entries.
Recommendations Update to version 1.7.0 or later. This version adds deferred Radio cleanup in the serveConn SCTP server, ensuring every connection exit path removes the radio, and removes the stale-entry scan from SCTP Notification handling.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33904
GHSA-9H59-P45G-445H
GO-2026-4874
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1205-1

Produtos afetados

Ella Core