Re: ZDI-CAN-29089: New Vulnerability Report
Willy Tarreau <[email protected]> Tue, 10 Feb 2026 18:01:39 +0100
| Newsgroups | dev.linux.lists.ofono |
|---|---|
| Message-ID | <[email protected]> |
Hello, On Tue, Feb 10, 2026 at 04:54:46PM +0000, [email protected] wrote: > ZDI-CAN-29089: oFono MBIM SMS Handling Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability > > -- CVSS ----------------------------------------- > > 6.8: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H > > -- ABSTRACT ------------------------------------- > > Trend Micro's Zero Day Initiative has identified a vulnerability affecting the following products: > oFono - oFono > > -- VULNERABILITY DETAILS ------------------------ > * Version tested:20.0.3 > * Installer file:agl-demo-platform-crosssdk-raspberrypi4-64.wic.xz > * Platform tested:Raspberry Pi (...) Please note that none of these 3 reports concern code in the Linux kernel, so [email protected] can be dropped from future exchanges. Thanks, Willy