Re: ZDI-CAN-29089: New Vulnerability Report
Sicelo <[email protected]> Thu, 12 Mar 2026 22:13:37 +0200
| Newsgroups | dev.linux.lists.ofono |
|---|---|
| Message-ID | <[email protected]> |
Hi Community members will work on these. As with any other open-source projects, patches welcome. Best Regards On Thu, Mar 12, 2026 at 07:13:20PM +0000, [email protected] wrote: > Hello Willy, > > Noted thank you! > > Any updates on this issue? > > Thanks, > ZDI > > -----Original Message----- > From: Willy Tarreau <[email protected]> > Sent: Tuesday, February 10, 2026 9:02 AM > To: ZDI Disclosures Mailbox <[email protected]> > Cc: [email protected]; [email protected]; [email protected] > Subject: Re: ZDI-CAN-29089: New Vulnerability Report > > Hello, > > On Tue, Feb 10, 2026 at 04:54:46PM +0000, [email protected] wrote: > > ZDI-CAN-29089: oFono MBIM SMS Handling Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability > > > > -- CVSS ----------------------------------------- > > > > 6.8: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H > > > > -- ABSTRACT ------------------------------------- > > > > Trend Micro's Zero Day Initiative has identified a vulnerability affecting the following products: > > oFono - oFono > > > > -- VULNERABILITY DETAILS ------------------------ > > * Version tested:20.0.3 > > * Installer file:agl-demo-platform-crosssdk-raspberrypi4-64.wic.xz > > * Platform tested:Raspberry Pi > (...) > > Please note that none of these 3 reports concern code in the Linux > kernel, so [email protected] can be dropped from future exchanges. > > Thanks, > Willy > TREND MICRO EMAIL NOTICE > The information contained in this email and any attachments is confidential > and may be subject to copyright or other intellectual property protection. > If you are not the intended recipient, you are not authorized to use or > disclose this information, and we request that you notify us by reply mail or > telephone and delete the original message from your mail system. > For details about what personal information we collect and why, please see our Privacy Notice on our website at: [ https://www.trendmicro.com/privacy] > >