Sceawere
Vulnerability Detail
CVE-2026-82549UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Magma SecurityModeComplete Integrity Validation Failure
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.3
- Creation Date
- 3h ago
- Vendor
- Linux Foundation
- Product
- Magma
- Attack Type
- Improper Validation of Integrity Check Value
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be launched remotely. The exploit is publicly available and might be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.3",
"pubDate": "2026-08-30T16:16:43.667Z",
"pubdate": "2026-08-30T16:16:43.667Z",
"executiveSummary": "A critical vulnerability has been identified in the Linux Foundation Magma 1.9.0 release, specifically within the SecurityModeComplete Handler component.\nThe vulnerability is classified as an improper validation of integrity check value, allowing for the potential bypass of security mechanisms during the NAS (Non-Access Stratum) security mode control procedure.\nThis flaw allows remote attackers to manipulate security parameters, potentially leading to unauthorized access or the interception of communication within the network infrastructure.\nThe vulnerability is currently exposed to public exploit availability, significantly increasing the risk of active exploitation by threat actors.\nGiven that the component is responsible for the cryptographic security context of the UE (User Equipment), the successful exploitation of this vulnerability has severe implications for the confidentiality and integrity of the 5G or LTE signaling plane.\nThere are no requirements for local access; the vulnerability is remotely exploitable, necessitating immediate assessment of exposed interfaces and deployment of available security controls.",
"technicalDetails": "The vulnerability resides in the SecurityModeComplete Handler component of Linux Foundation Magma version 1.9.0. The root cause is a failure to rigorously validate the integrity check value (ICV) provided during the Security Mode Complete procedure.\nIn 3GPP standards, the Security Mode Command and Security Mode Complete messages are critical for establishing integrity protection and ciphering between the UE and the core network (AMF/MME). The SecurityModeComplete Handler is expected to verify that the message content has not been tampered with by validating the Message Authentication Code for Integrity (MAC-I).\nIn Magma 1.9.0, the implementation fails to enforce strict checks on these values. An attacker capable of injecting or intercepting signaling traffic can craft a malicious SecurityModeComplete message. By manipulating the ICV fields, the attacker can force the handler to accept an unauthenticated or improperly constructed security state.\nThe attack flow involves the following steps: 1) The attacker initiates or intercepts a connection between a UE and the Magma-based core network. 2) The network sends a SecurityModeCommand. 3) The attacker intercepts or intercepts the UE response and injects a crafted SecurityModeComplete message. 4) The SecurityModeComplete Handler, due to flawed validation logic, processes the packet without verifying the cryptographic signature (MAC-I) against the established security context. 5) The network proceeds to move the UE into a state where security protections are either downgraded or entirely absent, based on the attacker's payload.\nBecause the vulnerability exists at the protocol handler level, it does not require authentication from the attacker's perspective, as the attack occurs during the signaling phase before security context is fully established. This exposure is remote and impacts the signaling plane's integrity. Post-exploitation, the attacker may be capable of performing Man-in-the-Middle (MitM) attacks on subsequent user plane traffic, data spoofing, or unauthorized command injection, as the signaling plane no longer enforces the expected cryptographic assurances."
}