Re: ZDI-CAN-29089: New Vulnerability Report
Morgan Hughes <[email protected]> Thu, 12 Mar 2026 13:32:37 -0700
| Newsgroups | dev.linux.lists.ofono |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --------------XRNfIUndevMGWEP8jBBh8lW0 Content-Type: multipart/alternative; boundary="------------uOfmbM0by1jXN1c4vmLhn9LF" --------------uOfmbM0by1jXN1c4vmLhn9LF Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit On 2026-03-12 13:13, Sicelo wrote: > Community members will work on these. As with any other open-source > projects, patches welcome. This looks a lot like a problem I encountered on a buggy modem in October and submitted a patch for. I've re-attached the patch here, perhaps it was missed because I didn't submit it using git? Morgan Hughes > > > > On Thu, Mar 12, 2026 at 07:13:20PM +0000,[email protected] wrote: >> Hello Willy, >> >> Noted thank you! >> >> Any updates on this issue? >> >> Thanks, >> ZDI >> >> -----Original Message----- >> From: Willy Tarreau<[email protected]> >> Sent: Tuesday, February 10, 2026 9:02 AM >> To: ZDI Disclosures Mailbox<[email protected]> >> Cc:[email protected];[email protected];[email protected] >> Subject: Re: ZDI-CAN-29089: New Vulnerability Report >> >> Hello, >> >> On Tue, Feb 10, 2026 at 04:54:46PM +0000,[email protected] wrote: >>> ZDI-CAN-29089: oFono MBIM SMS Handling Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability >>> >>> -- CVSS ----------------------------------------- >>> >>> 6.8: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H >>> >>> -- ABSTRACT ------------------------------------- >>> >>> Trend Micro's Zero Day Initiative has identified a vulnerability affecting the following products: >>> oFono - oFono >>> >>> -- VULNERABILITY DETAILS ------------------------ >>> * Version tested:20.0.3 >>> * Installerfile:agl-demo-platform-crosssdk-raspberrypi4-64.wic.xz >>> * Platform tested:Raspberry Pi >> (...) >> >> Please note that none of these 3 reports concern code in the Linux >> kernel, [email protected] can be dropped from future exchanges. >> >> Thanks, >> Willy >> TREND MICRO EMAIL NOTICE >> The information contained in this email and any attachments is confidential >> and may be subject to copyright or other intellectual property protection. >> If you are not the intended recipient, you are not authorized to use or >> disclose this information, and we request that you notify us by reply mail or >> telephone and delete the original message from your mail system. >> For details about what personal information we collect and why, please see our Privacy Notice on our website at: [https://www.trendmicro.com/privacy] >> >> --------------uOfmbM0by1jXN1c4vmLhn9LF Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 8bit <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> </head> <body> <div class="moz-cite-prefix">On 2026-03-12 13:13, Sicelo wrote:<br> </div> <blockquote type="cite" cite="mid:[email protected]"> <pre wrap="" class="moz-quote-pre">Community members will work on these. As with any other open-source projects, patches welcome.</pre> </blockquote> <p>This looks a lot like a problem I encountered on a buggy modem in October and submitted a patch for. I've re-attached the patch here, perhaps it was missed because I didn't submit it using git?</p> <p>Morgan Hughes</p> <p><br> </p> <blockquote type="cite" cite="mid:[email protected]"> <pre wrap="" class="moz-quote-pre"> On Thu, Mar 12, 2026 at 07:13:20PM +0000, <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a> wrote: </pre> <blockquote type="cite"> <pre wrap="" class="moz-quote-pre">Hello Willy, Noted thank you! Any updates on this issue? Thanks, ZDI -----Original Message----- From: Willy Tarreau <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]"><[email protected]></a> Sent: Tuesday, February 10, 2026 9:02 AM To: ZDI Disclosures Mailbox <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]"><[email protected]></a> Cc: <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>; <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>; <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a> Subject: Re: ZDI-CAN-29089: New Vulnerability Report Hello, On Tue, Feb 10, 2026 at 04:54:46PM +0000, <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a> wrote: </pre> <blockquote type="cite"> <pre wrap="" class="moz-quote-pre">ZDI-CAN-29089: oFono MBIM SMS Handling Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability -- CVSS ----------------------------------------- 6.8: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H -- ABSTRACT ------------------------------------- Trend Micro's Zero Day Initiative has identified a vulnerability affecting the following products: oFono - oFono -- VULNERABILITY DETAILS ------------------------ * Version tested:20.0.3 * Installer <a class="moz-txt-link-freetext" href="file:agl-demo-platform-crosssdk-raspberrypi4-64.wic.xz">file:agl-demo-platform-crosssdk-raspberrypi4-64.wic.xz</a> * Platform tested:Raspberry Pi </pre> </blockquote> <pre wrap="" class="moz-quote-pre">(...) Please note that none of these 3 reports concern code in the Linux kernel, so <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a> can be dropped from future exchanges. Thanks, Willy TREND MICRO EMAIL NOTICE The information contained in this email and any attachments is confidential and may be subject to copyright or other intellectual property protection. If you are not the intended recipient, you are not authorized to use or disclose this information, and we request that you notify us by reply mail or telephone and delete the original message from your mail system. For details about what personal information we collect and why, please see our Privacy Notice on our website at: [ <a class="moz-txt-link-freetext" href="https://www.trendmicro.com/privacy">https://www.trendmicro.com/privacy</a>] </pre> </blockquote> <pre wrap="" class="moz-quote-pre"> </pre> </blockquote> <p><br> </p> </body> </html> --------------uOfmbM0by1jXN1c4vmLhn9LF-- --------------XRNfIUndevMGWEP8jBBh8lW0 Content-Type: text/x-patch; charset=UTF-8; name="mbim-header-validate.patch" Content-Disposition: attachment; filename="mbim-header-validate.patch" Content-Transfer-Encoding: base64 ZGlmZiAtLWdpdCBhL2RyaXZlcnMvbWJpbW1vZGVtL21iaW0uYyBiL2RyaXZlcnMvbWJpbW1v ZGVtL21iaW0uYwppbmRleCBjNDA1NzYxZC4uNDMyMmY1YWQgMTAwNjQ0Ci0tLSBhL2RyaXZl cnMvbWJpbW1vZGVtL21iaW0uYworKysgYi9kcml2ZXJzL21iaW1tb2RlbS9tYmltLmMKQEAg LTE4LDYgKzE4LDcgQEAKICNpbmNsdWRlIDxsaW51eC90eXBlcy5oPgogCiAjaW5jbHVkZSA8 ZWxsL2VsbC5oPgorI2luY2x1ZGUgPGVsbC91c2VmdWwuaD4KIAogI2luY2x1ZGUgIm1iaW0u aCIKICNpbmNsdWRlICJtYmltLW1lc3NhZ2UuaCIKQEAgLTYxMyw2ICs2MTQsMTUgQEAgc3Rh dGljIGJvb2wgY29tbWFuZF9yZWFkX2hhbmRsZXIoc3RydWN0IGxfaW8gKmlvLCB2b2lkICp1 c2VyX2RhdGEpCiAJaGRyID0gKHN0cnVjdCBtYmltX21lc3NhZ2VfaGVhZGVyICopIGRldmlj ZS0+aGVhZGVyOwogCXR5cGUgPSBMX0xFMzJfVE9fQ1BVKGhkci0+dHlwZSk7CiAKKwlpZiAo dW5saWtlbHkoaGRyLT5sZW4gPiBNQVhfQ09OVFJPTF9UUkFOU0ZFUikpIHsKKwkJY2hhciAq aGV4ID0gbF91dGlsX2hleHN0cmluZyhkZXZpY2UtPmhlYWRlciwKKwkJCQkJCXNpemVvZihz dHJ1Y3QgbWJpbV9tZXNzYWdlX2hlYWRlcikpOworCQlsX3dhcm4oIk1CSU06IHNraXAgaW1w bGF1c2libGUgaGRyICVzOiBsZW4gMHgleCB0eXBlIDB4JXgiLCBoZXgsCisJCQlMX0xFMzJf VE9fQ1BVKGhkci0+bGVuKSwgTF9MRTMyX1RPX0NQVShoZHItPnR5cGUpKTsKKwkJbF9mcmVl KGhleCk7CisJCXJldHVybiBmYWxzZTsKKwl9CisKIAlpZiAoZGV2aWNlLT5zZWdtZW50X2J5 dGVzX3JlbWFpbmluZyA9PSAwKQogCQlkZXZpY2UtPnNlZ21lbnRfYnl0ZXNfcmVtYWluaW5n ID0KIAkJCQkJTF9MRTMyX1RPX0NQVShoZHItPmxlbikgLQo= --------------XRNfIUndevMGWEP8jBBh8lW0--