Stack Overflow Bug in ofono's Decode_Deliver_Report Function Could Lead to SMS Attacks
CVE-2023-4235

Currently unrated

Key Information:

Vendor

Fedora

Vendor
CVE Published:
17 April 2024

What is CVE-2023-4235?

A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_deliver_report().

Affected Version(s)

ofono 2.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Mitch Zakocs (Trend Micro Zero Day Initiative) for reporting this issue.
.