CVE-2026-75893

NameCVE-2026-75893
DescriptionIn osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg()  function via IPA frame lengths.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1148556

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
osmo-bsc (PTS)bookworm1.9.0-3vulnerable
forky, sid, trixie1.13.0-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
osmo-bscsource(unstable)(unfixed)1148556

Notes

[trixie] - osmo-bsc <no-dsa> (Minor issue)
Fixed by: https://cgit.osmocom.org/osmo-bsc/commit/?id=2852a03c153cd9418c2a86d0b2193ac41169dbb7

Search for package or bug name: Reporting problems