Out-of-Bound Read Vulnerability in Libsmpp35 by Osmocom
CVE-2026-75895

Currently unrated

Key Information:

Vendor

Osmocom

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-75895?

An out-of-bound read vulnerability has been identified in Libsmpp35 versions 0.1.0 through 1.8.0, specifically in the smpp34_unpack() function. This issue can be exploited through attacker-controlled SMPP PDUs, which may lead to memory corruption. Users of affected versions should apply the necessary patches to mitigate security risks as outlined in the available references.

Affected Version(s)

libsmpp34 1.10.0 < 1.14.5

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nikolas Null "n0k0" - Security Researcher at mnemonic
.