Magma Mobile Management Entity Null Pointer Dereference Vulnerability

Vulnerability

A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) component of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP 'E-RAB Release Response' packet that lacks the required 'MME_UE_S1AP_ID' field. The issue has been fixed in Magma version 1.9.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing the MME to crash and disrupt cellular communications managed by the MME.

Reproduction

To reproduce this vulnerability, send an S1AP 'E-RAB Release Response' packet to the Magma MME. The packet must be crafted to omit the 'MME_UE_S1AP_ID' field. This can be done by using a network tool or script that allows for the manipulation of S1AP message contents. Once the packet is sent, the MME will crash, demonstrating the vulnerability.

Remediation

Users can upgrade to Magma version 1.9 or later, where this vulnerability has been fixed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
9.1
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.