CVE-2026-33904
Last modified
CVE-2026-33904 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, a deadlock in the AMF's SCTP notification handler causes the entire AMF control plane to hang until the process is restarted. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, a deadlock in the AMF's SCTP notification handler causes the entire AMF control plane to hang until the process is restarted. An attacker with access to the N2 interface can cause Ella Core to hang, resulting in a denial of service for all subscribers. Version 1.7.0 adds deferred Radio cleanup in serveConn SCTP server so that every connection exit path removes the radio. Remove the stale-entry scan from SCTP Notification handling.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ellanetworks | Ella Core | < 1.7.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-33904?
How severe is CVE-2026-33904?
How do I fix CVE-2026-33904?
Are you affected by CVE-2026-33904?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
