#1149673 modemmanager: CVE-2026-95622

Package:
src:modemmanager
Source:
src:modemmanager
Submitter:
Salvatore Bonaccorso
Date:
2026-10-02 07:39:19 UTC
Severity:
normal
Tags:
#1149673#5
Date:
2026-10-02 07:10:41 UTC
From:
To:
Hi,

The following vulnerability was published for modemmanager.

CVE-2026-95622[0]:
| Reachable assertion in Cell Broadcast encoding parse causes denial
| of service

Unfortunately at time of writing this bugreport there was only the
bugzilla reference from Red Hat. What is the upstream status?

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-95622
https://www.cve.org/CVERecord?id=CVE-2026-95622
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2540006

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1149673#10
Date:
2026-10-02 07:25:10 UTC
From:
To:
Hi,

I fixed a bunch of things in that area in 1.25.x so I would assume it is
fixed upstream but with the information in the report that is hard to
tell atm. I just wish they would attach the payload.

Cheers,
 -- Guido