RE: ZDI-CAN-29089: New Vulnerability Report
| Newsgroups | dev.linux.lists.ofono |
|---|---|
| Message-ID | <BYAPR01MB38300A127FB5267EA5A6846E8044A@BYAPR01MB3830.prod.exchangelabs.com> |
Hello Willy, Noted thank you! Any updates on this issue? Thanks, ZDI -----Original Message----- From: Willy Tarreau <[email protected]> Sent: Tuesday, February 10, 2026 9:02 AM To: ZDI Disclosures Mailbox <[email protected]> Cc: [email protected]; [email protected]; [email protected] Subject: Re: ZDI-CAN-29089: New Vulnerability Report Hello, On Tue, Feb 10, 2026 at 04:54:46PM +0000, [email protected] = wrote: > ZDI-CAN-29089: oFono MBIM SMS Handling Heap-based Buffer Overflow Arbit= rary Code Execution Vulnerability > > -- CVSS ----------------------------------------- > > 6.8: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H > > -- ABSTRACT ------------------------------------- > > Trend Micro's Zero Day Initiative has identified a vulnerability affect= ing the following products: > oFono - oFono > > -- VULNERABILITY DETAILS ------------------------ > * Version tested:20.0.3 > * Installer file:agl-demo-platform-crosssdk-raspberrypi4-64.wic.xz > * Platform tested:Raspberry Pi (...) Please note that none of these 3 reports concern code in the Linux kernel, so [email protected] can be dropped from future exchanges. Thanks, Willy TREND MICRO EMAIL NOTICE The information contained in this email and any attachments is confidenti= al and may be subject to copyright or other intellectual property protection= . If you are not the intended recipient, you are not authorized to use or disclose this information, and we request that you notify us by reply mai= l or telephone and delete the original message from your mail system. For details about what personal information we collect and why, please se= e our Privacy Notice on our website at: [ https://www.trendmicro.com/priv= acy]