Heap-Based Buffer Overflow in osmo-bsc by Osmocom
CVE-2026-75893

Currently unrated

Key Information:

Vendor

Osmocom

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-75893?

A heap-based buffer overflow vulnerability has been identified in the ipaccess_proxy_read_msg() function of osmo-bsc, affecting version 1.0.1 through 1.14.1. This issue arises from improper handling of IPA frame lengths, potentially allowing attackers to exploit the flaw, leading to unauthorized access, data corruption, or disruption of services. A patch has been released to mitigate this vulnerability, emphasizing the need for users to update to secure versions.

Affected Version(s)

osmo-bsc 1.0.1 < 1.14.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nikolas Null "n0k0" - Security Researcher at mnemonic
.