openSUSE-SU-2026:21154-1

    Dashboard / Vulnerabilities / openSUSE-SU-2026:21154-1

    openSUSE-SU-2026:21154-1

    Published: 23 Jun 2026Last Modified: 30 Jun 2026

    Summary: Security update for ofono

    Details: This update for ofono fixes the following issues: Changes in ofono: - Reference the tracking bugs for the SMS/STK/USSD decoder security fixes applied upstream across the 2.14-2.17 updates: * SMS decoder stack buffer overflows: CVE-2023-2794 (boo#1218292), CVE-2023-4232 (boo#1218293), CVE-2023-4233 (boo#1218294), CVE-2023-4234 (boo#1218295), CVE-2023-4235 (boo#1218296) * SMS PDU / message-list parsing overflows and OOB read: CVE-2024-7537 (boo#1228903), CVE-2024-7547 (boo#1228917) * AT-command / USSD response parsing overflows: CVE-2024-7538 (boo#1228904), CVE-2024-7539 (boo#1228905) * Uninitialized-memory information disclosure: CVE-2024-7540 (boo#1228906), CVE-2024-7541 (boo#1228907), CVE-2024-7542 (boo#1228908) * STK command PDU heap overflows: CVE-2024-7543 (boo#1228910), CVE-2024-7544 (boo#1228913), CVE-2024-7545 (boo#1228914), CVE-2024-7546 (boo#1228916) - Update to version 2.19 * Add support for PPP reset workaround for SIM7100 modem. * Add support for Qualcomm RAW-IP only devices. - Update to version 2.18 * Fix issue with QMI and handling SMS message acknowledgement. * Fix issue with handling SIM7100 modem ready detection. * Add support for forbidden operator list. - Update to version 2.17 * Fix issue with SMS and possible buffer overflow. - Update to version 2.16 * Add support for QMI service request rate limiting. - Update to version 2.15 * Fix issue with SMS and uninitialized buffers. * Fix issue with USSD and uninitialized buffers. * Add support for the Test Anything Protocol. - Update to version 2.14 * Fix issue with STK and buffer length checks. * Fix issue with SMS and buffer length checks. * Fix issue with QMI and handling RAT detection. * Fix issue with QMI and handling call forwarding. * Add support for handling MHI network interfaces. - Update to version 2.13 * Add support for handling QMI PIN and Lock methods. * Add support for handling QMI WWAN interfaces. * Add support for handling RMNet interfaces. - Update to version 2.12 * Fix issue with access technology reporting. * Fix issue with detecting Phonet devices. - Update to version 2.11 * Add support for SIMCom A7672E-FASE modem. * Add support for Quectel EG916Q-GL modem.

    Affected packages

    Package

    Name: ofono

    Purl: pkg:rpm/opensuse/ofono&distro=openSUSE%20Leap%2016.0

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.19-bp160.1.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    openSUSE-SU-2026:21154-1 | CVE-DB