CVE-2026-33904 Details
Description
Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, a deadlock in the AMF's SCTP notification handler causes the entire AMF control plane to hang until the process is restarted. An attacker with access to the N2 interface can cause Ella Core to hang, resulting in a denial of service for all subscribers. Version 1.7.0 adds deferred Radio cleanup in serveConn SCTP server so that every connection exit path removes the radio. Remove the stale-entry scan from SCTP Notification handling.
A deadlock vulnerability has been identified in the Ella Core 5G core network solution for private networks, specifically in versions prior to 1.7.0. The issue arises in the Access and Mobility Management Function (AMF) SCTP notification handler, where a deadlock can cause the entire AMF control plane to freeze, disrupting service for all subscribers. This denial-of-service condition persists until the process is manually restarted. The vulnerability can be exploited by an attacker with access to the N2 interface.
Users can upgrade to Ella Core version 1.7.0 or later, which includes the necessary fix. Instructions for downloading this version are available on the Ella Networks GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-833 | Deadlock | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ellanetworks ella core | < 1.7.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 20, 2026 | Initial Analysis | [email protected] |
| Mar 27, 2026 | New CVE Received | [email protected] |