Re: ZDI-CAN-29089: New Vulnerability Report

Willy Tarreau <[email protected]> Tue, 10 Feb 2026 18:01:39 +0100
Newsgroups dev.linux.lists.ofono
Message-ID <[email protected]>
Hello,

On Tue, Feb 10, 2026 at 04:54:46PM +0000, [email protected] wrote:
> ZDI-CAN-29089: oFono MBIM SMS Handling Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability
> 
> -- CVSS -----------------------------------------
> 
> 6.8: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
> 
> -- ABSTRACT -------------------------------------
> 
> Trend Micro's Zero Day Initiative has identified a vulnerability affecting the following products:
> oFono - oFono
> 
> -- VULNERABILITY DETAILS ------------------------
> * Version tested:20.0.3
> * Installer file:agl-demo-platform-crosssdk-raspberrypi4-64.wic.xz
> * Platform tested:Raspberry Pi
(...)

Please note that none of these 3 reports concern code in the Linux
kernel, so [email protected] can be dropped from future exchanges.

Thanks,
Willy