Stack Overflow Bug in ofono Affects SMS Decoding
CVE-2023-4233

Currently unrated

Key Information:

Vendor

Fedora

Vendor
CVE Published:
17 April 2024

What is CVE-2023-4233?

A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the sms_decode_address_field() function during the SMS PDU decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS.

Affected Version(s)

ofono 2.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Mitch Zakocs (Trend Micro Zero Day Initiative) for reporting this issue.
.