openSUSE-SU-2026:21154-1
Dashboard / Vulnerabilities / openSUSE-SU-2026:21154-1
openSUSE-SU-2026:21154-1
Summary: Security update for ofono
Details: This update for ofono fixes the following issues: Changes in ofono: - Reference the tracking bugs for the SMS/STK/USSD decoder security fixes applied upstream across the 2.14-2.17 updates: * SMS decoder stack buffer overflows: CVE-2023-2794 (boo#1218292), CVE-2023-4232 (boo#1218293), CVE-2023-4233 (boo#1218294), CVE-2023-4234 (boo#1218295), CVE-2023-4235 (boo#1218296) * SMS PDU / message-list parsing overflows and OOB read: CVE-2024-7537 (boo#1228903), CVE-2024-7547 (boo#1228917) * AT-command / USSD response parsing overflows: CVE-2024-7538 (boo#1228904), CVE-2024-7539 (boo#1228905) * Uninitialized-memory information disclosure: CVE-2024-7540 (boo#1228906), CVE-2024-7541 (boo#1228907), CVE-2024-7542 (boo#1228908) * STK command PDU heap overflows: CVE-2024-7543 (boo#1228910), CVE-2024-7544 (boo#1228913), CVE-2024-7545 (boo#1228914), CVE-2024-7546 (boo#1228916) - Update to version 2.19 * Add support for PPP reset workaround for SIM7100 modem. * Add support for Qualcomm RAW-IP only devices. - Update to version 2.18 * Fix issue with QMI and handling SMS message acknowledgement. * Fix issue with handling SIM7100 modem ready detection. * Add support for forbidden operator list. - Update to version 2.17 * Fix issue with SMS and possible buffer overflow. - Update to version 2.16 * Add support for QMI service request rate limiting. - Update to version 2.15 * Fix issue with SMS and uninitialized buffers. * Fix issue with USSD and uninitialized buffers. * Add support for the Test Anything Protocol. - Update to version 2.14 * Fix issue with STK and buffer length checks. * Fix issue with SMS and buffer length checks. * Fix issue with QMI and handling RAT detection. * Fix issue with QMI and handling call forwarding. * Add support for handling MHI network interfaces. - Update to version 2.13 * Add support for handling QMI PIN and Lock methods. * Add support for handling QMI WWAN interfaces. * Add support for handling RMNet interfaces. - Update to version 2.12 * Fix issue with access technology reporting. * Fix issue with detecting Phonet devices. - Update to version 2.11 * Add support for SIMCom A7672E-FASE modem. * Add support for Quectel EG916Q-GL modem.
References: , https://bugzilla.suse.com/1218292, https://bugzilla.suse.com/1218293, https://bugzilla.suse.com/1218294, https://bugzilla.suse.com/1218295, https://bugzilla.suse.com/1218296, https://bugzilla.suse.com/1228903, https://bugzilla.suse.com/1228904, https://bugzilla.suse.com/1228905, https://bugzilla.suse.com/1228906, https://bugzilla.suse.com/1228907, https://bugzilla.suse.com/1228908, https://bugzilla.suse.com/1228910, https://bugzilla.suse.com/1228913, https://bugzilla.suse.com/1228914, https://bugzilla.suse.com/1228916, https://bugzilla.suse.com/1228917, https://www.suse.com/security/cve/CVE-2023-2794, https://www.suse.com/security/cve/CVE-2023-4232, https://www.suse.com/security/cve/CVE-2023-4233, https://www.suse.com/security/cve/CVE-2023-4234, https://www.suse.com/security/cve/CVE-2023-4235, https://www.suse.com/security/cve/CVE-2024-7537, https://www.suse.com/security/cve/CVE-2024-7538, https://www.suse.com/security/cve/CVE-2024-7539, https://www.suse.com/security/cve/CVE-2024-7540, https://www.suse.com/security/cve/CVE-2024-7541, https://www.suse.com/security/cve/CVE-2024-7542, https://www.suse.com/security/cve/CVE-2024-7543, https://www.suse.com/security/cve/CVE-2024-7544, https://www.suse.com/security/cve/CVE-2024-7545, https://www.suse.com/security/cve/CVE-2024-7546, https://www.suse.com/security/cve/CVE-2024-7547
Affected packages
Package
Name: ofono
Purl: pkg:rpm/opensuse/ofono&distro=openSUSE%20Leap%2016.0
Affected ranges
Type: ECOSYSTEM
Events:
