Re: ZDI-CAN-29089: New Vulnerability Report

Morgan Hughes <[email protected]> Thu, 12 Mar 2026 13:32:37 -0700
Newsgroups dev.linux.lists.ofono
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--------------XRNfIUndevMGWEP8jBBh8lW0
Content-Type: multipart/alternative;
 boundary="------------uOfmbM0by1jXN1c4vmLhn9LF"

--------------uOfmbM0by1jXN1c4vmLhn9LF
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

On 2026-03-12 13:13, Sicelo wrote:
> Community members will work on these. As with any other open-source
> projects, patches welcome.

This looks a lot like a problem I encountered on a buggy modem in October and submitted a 
patch for.  I've re-attached the patch here, perhaps it was missed because I didn't submit 
it using git?

Morgan Hughes


>
>
>
> On Thu, Mar 12, 2026 at 07:13:20PM +0000,[email protected] wrote:
>> Hello Willy,
>>
>> Noted thank you!
>>
>> Any updates on this issue?
>>
>> Thanks,
>> ZDI
>>
>> -----Original Message-----
>> From: Willy Tarreau<[email protected]>
>> Sent: Tuesday, February 10, 2026 9:02 AM
>> To: ZDI Disclosures Mailbox<[email protected]>
>> Cc:[email protected];[email protected];[email protected]
>> Subject: Re: ZDI-CAN-29089: New Vulnerability Report
>>
>> Hello,
>>
>> On Tue, Feb 10, 2026 at 04:54:46PM +0000,[email protected] wrote:
>>> ZDI-CAN-29089: oFono MBIM SMS Handling Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability
>>>
>>> -- CVSS -----------------------------------------
>>>
>>> 6.8: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
>>>
>>> -- ABSTRACT -------------------------------------
>>>
>>> Trend Micro's Zero Day Initiative has identified a vulnerability affecting the following products:
>>> oFono - oFono
>>>
>>> -- VULNERABILITY DETAILS ------------------------
>>> * Version tested:20.0.3
>>> * Installerfile:agl-demo-platform-crosssdk-raspberrypi4-64.wic.xz
>>> * Platform tested:Raspberry Pi
>> (...)
>>
>> Please note that none of these 3 reports concern code in the Linux
>> kernel, [email protected] can be dropped from future exchanges.
>>
>> Thanks,
>> Willy
>> TREND MICRO EMAIL NOTICE
>> The information contained in this email and any attachments is confidential
>> and may be subject to copyright or other intellectual property protection.
>> If you are not the intended recipient, you are not authorized to use or
>> disclose this information, and we request that you notify us by reply mail or
>> telephone and delete the original message from your mail system.
>> For details about what personal information we collect and why, please see our Privacy Notice on our website at: [https://www.trendmicro.com/privacy]
>>
>>

--------------uOfmbM0by1jXN1c4vmLhn9LF
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <div class="moz-cite-prefix">On 2026-03-12 13:13, Sicelo wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:[email protected]">
      <pre wrap="" class="moz-quote-pre">Community members will work on these. As with any other open-source
projects, patches welcome.</pre>
    </blockquote>
    <p>This looks a lot like a problem I encountered on a buggy modem in
      October and submitted a patch for.  I've re-attached the patch
      here, perhaps it was missed because I didn't submit it using git?</p>
    <p>Morgan Hughes</p>
    <p><br>
    </p>
    <blockquote type="cite"
      cite="mid:[email protected]">
      <pre wrap="" class="moz-quote-pre">



On Thu, Mar 12, 2026 at 07:13:20PM +0000, <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a> wrote:
</pre>
      <blockquote type="cite">
        <pre wrap="" class="moz-quote-pre">Hello Willy,

Noted thank you!

Any updates on this issue?

Thanks,
ZDI

-----Original Message-----
From: Willy Tarreau <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]">&lt;[email protected]&gt;</a>
Sent: Tuesday, February 10, 2026 9:02 AM
To: ZDI Disclosures Mailbox <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]">&lt;[email protected]&gt;</a>
Cc: <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>; <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>; <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
Subject: Re: ZDI-CAN-29089: New Vulnerability Report

Hello,

On Tue, Feb 10, 2026 at 04:54:46PM +0000, <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a> wrote:
</pre>
        <blockquote type="cite">
          <pre wrap="" class="moz-quote-pre">ZDI-CAN-29089: oFono MBIM SMS Handling Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability

-- CVSS -----------------------------------------

6.8: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

-- ABSTRACT -------------------------------------

Trend Micro's Zero Day Initiative has identified a vulnerability affecting the following products:
oFono - oFono

-- VULNERABILITY DETAILS ------------------------
* Version tested:20.0.3
* Installer <a class="moz-txt-link-freetext" href="file:agl-demo-platform-crosssdk-raspberrypi4-64.wic.xz">file:agl-demo-platform-crosssdk-raspberrypi4-64.wic.xz</a>
* Platform tested:Raspberry Pi
</pre>
        </blockquote>
        <pre wrap="" class="moz-quote-pre">(...)

Please note that none of these 3 reports concern code in the Linux
kernel, so <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a> can be dropped from future exchanges.

Thanks,
Willy
TREND MICRO EMAIL NOTICE
The information contained in this email and any attachments is confidential
and may be subject to copyright or other intellectual property protection.
If you are not the intended recipient, you are not authorized to use or
disclose this information, and we request that you notify us by reply mail or
telephone and delete the original message from your mail system.
For details about what personal information we collect and why, please see our Privacy Notice on our website at: [ <a class="moz-txt-link-freetext" href="https://www.trendmicro.com/privacy">https://www.trendmicro.com/privacy</a>]


</pre>
      </blockquote>
      <pre wrap="" class="moz-quote-pre">
</pre>
    </blockquote>
    <p><br>
    </p>
  </body>
</html>

--------------uOfmbM0by1jXN1c4vmLhn9LF--
--------------XRNfIUndevMGWEP8jBBh8lW0
Content-Type: text/x-patch; charset=UTF-8; name="mbim-header-validate.patch"
Content-Disposition: attachment; filename="mbim-header-validate.patch"
Content-Transfer-Encoding: base64

ZGlmZiAtLWdpdCBhL2RyaXZlcnMvbWJpbW1vZGVtL21iaW0uYyBiL2RyaXZlcnMvbWJpbW1v
ZGVtL21iaW0uYwppbmRleCBjNDA1NzYxZC4uNDMyMmY1YWQgMTAwNjQ0Ci0tLSBhL2RyaXZl
cnMvbWJpbW1vZGVtL21iaW0uYworKysgYi9kcml2ZXJzL21iaW1tb2RlbS9tYmltLmMKQEAg
LTE4LDYgKzE4LDcgQEAKICNpbmNsdWRlIDxsaW51eC90eXBlcy5oPgogCiAjaW5jbHVkZSA8
ZWxsL2VsbC5oPgorI2luY2x1ZGUgPGVsbC91c2VmdWwuaD4KIAogI2luY2x1ZGUgIm1iaW0u
aCIKICNpbmNsdWRlICJtYmltLW1lc3NhZ2UuaCIKQEAgLTYxMyw2ICs2MTQsMTUgQEAgc3Rh
dGljIGJvb2wgY29tbWFuZF9yZWFkX2hhbmRsZXIoc3RydWN0IGxfaW8gKmlvLCB2b2lkICp1
c2VyX2RhdGEpCiAJaGRyID0gKHN0cnVjdCBtYmltX21lc3NhZ2VfaGVhZGVyICopIGRldmlj
ZS0+aGVhZGVyOwogCXR5cGUgPSBMX0xFMzJfVE9fQ1BVKGhkci0+dHlwZSk7CiAKKwlpZiAo
dW5saWtlbHkoaGRyLT5sZW4gPiBNQVhfQ09OVFJPTF9UUkFOU0ZFUikpIHsKKwkJY2hhciAq
aGV4ID0gbF91dGlsX2hleHN0cmluZyhkZXZpY2UtPmhlYWRlciwKKwkJCQkJCXNpemVvZihz
dHJ1Y3QgbWJpbV9tZXNzYWdlX2hlYWRlcikpOworCQlsX3dhcm4oIk1CSU06IHNraXAgaW1w
bGF1c2libGUgaGRyICVzOiBsZW4gMHgleCB0eXBlIDB4JXgiLCBoZXgsCisJCQlMX0xFMzJf
VE9fQ1BVKGhkci0+bGVuKSwgTF9MRTMyX1RPX0NQVShoZHItPnR5cGUpKTsKKwkJbF9mcmVl
KGhleCk7CisJCXJldHVybiBmYWxzZTsKKwl9CisKIAlpZiAoZGV2aWNlLT5zZWdtZW50X2J5
dGVzX3JlbWFpbmluZyA9PSAwKQogCQlkZXZpY2UtPnNlZ21lbnRfYnl0ZXNfcmVtYWluaW5n
ID0KIAkJCQkJTF9MRTMyX1RPX0NQVShoZHItPmxlbikgLQo=

--------------XRNfIUndevMGWEP8jBBh8lW0--