| Name | CVE-2026-75892 |
| Description | In osmo-ggsn 1.14.0 an out of bounds write issue was found in theĀ gtp_decode_pdp_ctx() function through the PDP context GSN-Address sub-field, leading to memory corruption. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| osmo-ggsn (PTS) | bookworm | 1.9.0-3 | fixed |
| forky, sid, trixie | 1.13.0-2 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|
| osmo-ggsn | source | (unstable) | (not affected) | | | |
Notes
- osmo-ggsn <not-affected> (Vulnerable code introduced later)
Introduced in: https://cgit.osmocom.org/osmo-ggsn/commit/?id=d46d0cc3684522a053670946e1719d2520f3ac2a (1.14.0)
Fixed in: https://cgit.osmocom.org/osmo-ggsn/commit/?id=6c322f4dd339401a437da3c89c95f2bf64bca995 (1.15.0)