Ella Core didn't enforce security rules on concurrent running of security procedures defined in TS 33.501 §6.9.5.1 — it could send a NAS Security Mode Command while an N2 handover was still pending (and vice versa).
Concurrent Security Mode Command and N2 handover produce a KgNB mismatch between the UE and target gNB, causing the handover to fail. Requires a stalled gNB + re-registration race to trigger.
Ella Core now enforces both rules from §6.9.5.1, blocking concurrent Security Mode Command and N2 handover procedures.
{
"github_reviewed": true,
"github_reviewed_at": "2026-05-11T15:29:41Z",
"cwe_ids": [
"CWE-358"
],
"severity": "LOW",
"nvd_published_at": null
}