Back

HIGH

Ofono: sms decoder stack-based buffer overflow remote code execution vulnerability within the decode_status_report() function

Published Apr 17, 2024

Description

A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_status_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_status_report().

Affected products

Remediation

No remediation recorded yet.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner fedora
Published Apr 17, 2024
Updated Nov 4, 2025
Reserved Aug 8, 2023
CISA Vulnrichment
Updated Apr 23, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a