RE: ZDI-CAN-29089: New Vulnerability Report

"[email protected]" <[email protected]> Thu, 12 Mar 2026 19:13:20 +0000
Newsgroups dev.linux.lists.ofono
Message-ID <BYAPR01MB38300A127FB5267EA5A6846E8044A@BYAPR01MB3830.prod.exchangelabs.com>
Hello Willy,

Noted thank you!

Any updates on this issue?

Thanks,
ZDI

-----Original Message-----
From: Willy Tarreau <[email protected]> 
Sent: Tuesday, February 10, 2026 9:02 AM
To: ZDI Disclosures Mailbox <[email protected]>
Cc: [email protected]; [email protected]; [email protected]
Subject: Re: ZDI-CAN-29089: New Vulnerability Report

Hello,

On Tue, Feb 10, 2026 at 04:54:46PM +0000, [email protected] =
wrote:
> ZDI-CAN-29089: oFono MBIM SMS Handling Heap-based Buffer Overflow Arbit=
rary Code Execution Vulnerability
> 
> -- CVSS -----------------------------------------
> 
> 6.8: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
> 
> -- ABSTRACT -------------------------------------
> 
> Trend Micro's Zero Day Initiative has identified a vulnerability affect=
ing the following products:
> oFono - oFono
> 
> -- VULNERABILITY DETAILS ------------------------
> * Version tested:20.0.3
> * Installer file:agl-demo-platform-crosssdk-raspberrypi4-64.wic.xz
> * Platform tested:Raspberry Pi
(...)

Please note that none of these 3 reports concern code in the Linux
kernel, so [email protected] can be dropped from future exchanges.

Thanks,
Willy
TREND MICRO EMAIL NOTICE
The information contained in this email and any attachments is confidenti=
al
and may be subject to copyright or other intellectual property protection=
.
If you are not the intended recipient, you are not authorized to use or
disclose this information, and we request that you notify us by reply mai=
l or
telephone and delete the original message from your mail system.
For details about what personal information we collect and why, please se=
e our Privacy Notice on our website at: [ https://www.trendmicro.com/priv=
acy]