oFono could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8178-1 April 16, 2026 ofono vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: oFono could be made to crash if it received specially crafted input. Software Description: - ofono: A free software project for mobile telephony applications Details: It was discovered that oFono incorrectly handled crafted responses from AT commands. An attacker could possibly use this issue to crash the program, resulting in a denial of service or arbitrary code execution. (CVE-2024-7538, CVE-2024-7539, CVE-2024-7540, CVE-2024-7541, CVE-2024-7542) Lucas Leong discovered that oFono incorrectly handled crafted input. An attacker could possibly use this issue to crash the program, resulting in a denial of service or arbitrary code execution. (CVE-2024-7543, CVE-2024-7544, CVE-2024-7545, CVE-2024-7546, CVE-2024-7547) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS ofono 1.31-3ubuntu3.24.04.2+esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS ofono 1.31-3ubuntu1.2+esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS ofono 1.31-2ubuntu1+esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS ofono 1.21-1ubuntu1+esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS ofono 1.17.bzr6912+16.04.20160314.3-0ubuntu1+esm3 Available with Ubuntu Pro References: https://ubuntu.com/security/notices/USN-8178-1 CVE-2024-7538, CVE-2024-7539, CVE-2024-7540, CVE-2024-7541, CVE-2024-7542, CVE-2024-7543, CVE-2024-7544, CVE-2024-7545, CVE-2024-7546, CVE-2024-7547 . oFono crash risk identified in Ubuntu. Critical update instruction available for users across releases to mitigate threats.. oFono security, Ubuntu 24.04 LTS, Ubuntu 20.04 LTS, software update, denial of service. . Severity: Critical. LinuxSecurity.com Team
Sms decoder stack-based buffer overflow remote code execution vulnerability within the decode_deliver() function. (CVE-2023-2794) Sms decoder stack-based buffer overflow remote code execution vulnerability within the decode_status_report() function. (CVE-2023-4232) . MGASA-2025-0063 - Updated ofono packages fix security vulnerabilities Publication date: 13 Feb 2025 URL: https://advisories.mageia.org/MGASA-2025-0063.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-2794, CVE-2023-4232, CVE-2023-4233, CVE-2023-4234, CVE-2023-4235 Sms decoder stack-based buffer overflow remote code execution vulnerability within the decode_deliver() function. (CVE-2023-2794) Sms decoder stack-based buffer overflow remote code execution vulnerability within the decode_status_report() function. (CVE-2023-4232) Sms decoder stack-based buffer overflow remote code execution vulnerability within the sms_decode_address_field(). (CVE-2023-4233) Sms decoder stack-based buffer overflow remote code execution vulnerability within the decode_submit_report() function. (CVE-2023-4234) Sms decoder stack-based buffer overflow remote code execution vulnerability within the decode_deliver_report() function. (CVE-2023-4235) References: - https://bugs.mageia.org/show_bug.cgi?id=33841 - https://ubuntu.com/security/notices/USN-7141-1 - https://ubuntu.com/security/notices/USN-7151-1 - https://www.cve.org/CVERecord?id=CVE-2023-2794 - https://www.cve.org/CVERecord?id=CVE-2023-4232 - https://www.cve.org/CVERecord?id=CVE-2023-4233 - https://www.cve.org/CVERecord?id=CVE-2023-4234 - https://www.cve.org/CVERecord?id=CVE-2023-4235 SRPMS: - 9/core/ofono-2.1-1.1.mga9 . Recent updates to ofono packages in Mageia tackle significant security concerns, including vulnerabilities that allow for remote code execution.. ofono Security, Mageia Update, Remote Code Execution, Stack Overflow. . LinuxSecurity.com Team
Update to v2.14 . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-0051a464f1 2024-12-21 03:35:46.415725+00:00 -------------------------------------------------------------------------------- Name : ofono Product : Fedora 41 Version : 2.14 Release : 1.fc41 URL : https://www.intel.com/content/www/us/en/developer/topic-technology/open/overview.html Summary : Open Source Telephony Description : oFono.org is a place to bring developers together around designing an infrastructure for building mobile telephony (GSM/UMTS) applications. oFono includes a high-level D-Bus API for use by telephony applications. oFono also includes a low-level plug-in API for integrating with telephony stacks, cellular modems and storage back-ends. -------------------------------------------------------------------------------- Update Information: Update to v2.14 -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 12 2024 Artur Frenszek-Iwicki - 2.14-1 - Update to v2.14 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2303457 - CVE-2024-7547 ofono: oFono: Stack-based Buffer Overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303457 [ 2 ] Bug #2303595 - CVE-2024-7546 ofono: ofono: Buffer Overflow Privilege Escalation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303595 [ 3 ] Bug #2303597 - CVE-2024-7544 ofono: oFono: Heap-based Buffer Overflow Privilege Escalation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303597 [ 4 ] Bug #2303598 - CVE-2024-7543 ofono: oFono: Heap-based Buffer Overflow Privilege Escalation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303598 [ 5 ] Bug #2332134 - ofono-2.14 is available https://bugzilla.redhat.com/show_bug.cgi?id=2332134 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-0051a464f1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Backport upstream fixes for CVE-2023-4233 and CVE-2023-4234. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-e8a02e129e 2024-03-29 02:39:36.209054 -------------------------------------------------------------------------------- Name : ofono Product : Fedora 38 Version : 1.34 Release : 4.fc38 URL : Summary : Open Source Telephony Description : oFono.org is a place to bring developers together around designing an infrastructure for building mobile telephony (GSM/UMTS) applications. oFono includes a high-level D-Bus API for use by telephony applications. oFono also includes a low-level plug-in API for integrating with telephony stacks, cellular modems and storage back-ends. -------------------------------------------------------------------------------- Update Information: Backport upstream fixes for CVE-2023-4233 and CVE-2023-4234 -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 19 2024 Artur Frenszek-Iwicki - 1.34-4 - Backport upstream fix for CVE-2023-4233 and CVE-2023-4234 * Thu Jan 19 2023 Fedora Release Engineering - 1.34-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2255396 - CVE-2023-4233 ofono: SMS Decoder Stack-based Buffer Overflow Remote Code Execution Vulnerability within the sms_decode_address_field() function https://bugzilla.redhat.com/show_bug.cgi?id=2255396 [ 2 ] Bug #2255399 - CVE-2023-4234 ofono: SMS Decoder Stack-based Buffer Overflow Remote Code Execution Vulnerability within the decode_submit_report() function https://bugzilla.redhat.com/show_bug.cgi?id=2255399 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2024-e8a02e129e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to v2.5. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-c42ea059d0 2024-03-28 00:15:36.328468 -------------------------------------------------------------------------------- Name : ofono Product : Fedora 40 Version : 2.5 Release : 1.fc40 URL : Summary : Open Source Telephony Description : oFono.org is a place to bring developers together around designing an infrastructure for building mobile telephony (GSM/UMTS) applications. oFono includes a high-level D-Bus API for use by telephony applications. oFono also includes a low-level plug-in API for integrating with telephony stacks, cellular modems and storage back-ends. -------------------------------------------------------------------------------- Update Information: Update to v2.5 -------------------------------------------------------------------------------- ChangeLog: * Mon Mar 18 2024 Artur Frenszek-Iwicki - 2.5-1 - Update to v2.5 * Thu Jan 25 2024 Fedora Release Engineering - 1.34-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sun Jan 21 2024 Fedora Release Engineering - 1.34-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Thu Jul 20 2023 Fedora Release Engineering - 1.34-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Thu Jan 19 2023 Fedora Release Engineering - 1.34-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Fri Jul 22 2022 Fedora Release Engineering - 1.34-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2255387 - CVE-2023-2794 ofono: SMS Decoder Stack-based Buffer Overflow Remote Code Execution Vulnerability within the decode_deliver() function https://bugzilla.redhat.com/show_bug.cgi?id=2255387 [ 2 ] Bug #2255394 - CVE-2023-4232 ofono: SMSDecoder Stack-based Buffer Overflow Remote Code Execution Vulnerability within the decode_status_report() function https://bugzilla.redhat.com/show_bug.cgi?id=2255394 [ 3 ] Bug #2255396 - CVE-2023-4233 ofono: SMS Decoder Stack-based Buffer Overflow Remote Code Execution Vulnerability within the sms_decode_address_field() function https://bugzilla.redhat.com/show_bug.cgi?id=2255396 [ 4 ] Bug #2255399 - CVE-2023-4234 ofono: SMS Decoder Stack-based Buffer Overflow Remote Code Execution Vulnerability within the decode_submit_report() function https://bugzilla.redhat.com/show_bug.cgi?id=2255399 [ 5 ] Bug #2255402 - CVE-2023-4235 ofono: SMS Decoder Stack-based Buffer Overflow Remote Code Execution Vulnerability within the decode_deliver_report() function https://bugzilla.redhat.com/show_bug.cgi?id=2255402 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-c42ea059d0' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.