#1148556 osmo-bsc: CVE-2026-75893

Package:
src:osmo-bsc
Source:
src:osmo-bsc
Submitter:
Moritz Mühlenhoff
Date:
2026-09-20 19:25:01 UTC
Severity:
normal
Tags:
#1148556#5
Date:
2026-09-20 18:03:34 UTC
From:
To:
Hi,

The following vulnerability was published for osmo-bsc.

CVE-2026-75893[0]:
| In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow
| issue was found in the ipaccess_proxy_read_msg()  function via IPA
| frame lengths.

Fixed by: https://cgit.osmocom.org/osmo-bsc/commit/?id=2852a03c153cd9418c2a86d0b2193ac41169dbb7


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-75893
https://www.cve.org/CVERecord?id=CVE-2026-75893

Please adjust the affected versions in the BTS as needed.