openSUSE-SU-2026:21154-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21154-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21154-1
Upstream
CVE (16)
Related
Published
2026-06-23T13:07:52Z
Modified
2026-06-30T18:24:53Z
Summary
Security update for ofono
Details

This update for ofono fixes the following issues:

Changes in ofono:

  • Reference the tracking bugs for the SMS/STK/USSD decoder security fixes applied upstream across the 2.14-2.17 updates:

    • SMS decoder stack buffer overflows: CVE-2023-2794 (boo#1218292), CVE-2023-4232 (boo#1218293), CVE-2023-4233 (boo#1218294), CVE-2023-4234 (boo#1218295), CVE-2023-4235 (boo#1218296)
    • SMS PDU / message-list parsing overflows and OOB read: CVE-2024-7537 (boo#1228903), CVE-2024-7547 (boo#1228917)
    • AT-command / USSD response parsing overflows: CVE-2024-7538 (boo#1228904), CVE-2024-7539 (boo#1228905)
    • Uninitialized-memory information disclosure: CVE-2024-7540 (boo#1228906), CVE-2024-7541 (boo#1228907), CVE-2024-7542 (boo#1228908)
    • STK command PDU heap overflows: CVE-2024-7543 (boo#1228910), CVE-2024-7544 (boo#1228913), CVE-2024-7545 (boo#1228914), CVE-2024-7546 (boo#1228916)
  • Update to version 2.19

    • Add support for PPP reset workaround for SIM7100 modem.
    • Add support for Qualcomm RAW-IP only devices.
  • Update to version 2.18

    • Fix issue with QMI and handling SMS message acknowledgement.
    • Fix issue with handling SIM7100 modem ready detection.
    • Add support for forbidden operator list.
  • Update to version 2.17

    • Fix issue with SMS and possible buffer overflow.
  • Update to version 2.16

    • Add support for QMI service request rate limiting.
  • Update to version 2.15

    • Fix issue with SMS and uninitialized buffers.
    • Fix issue with USSD and uninitialized buffers.
    • Add support for the Test Anything Protocol.
  • Update to version 2.14

    • Fix issue with STK and buffer length checks.
    • Fix issue with SMS and buffer length checks.
    • Fix issue with QMI and handling RAT detection.
    • Fix issue with QMI and handling call forwarding.
    • Add support for handling MHI network interfaces.
  • Update to version 2.13

    • Add support for handling QMI PIN and Lock methods.
    • Add support for handling QMI WWAN interfaces.
    • Add support for handling RMNet interfaces.
  • Update to version 2.12

    • Fix issue with access technology reporting.
    • Fix issue with detecting Phonet devices.
  • Update to version 2.11

    • Add support for SIMCom A7672E-FASE modem.
    • Add support for Quectel EG916Q-GL modem.
References

Affected packages

openSUSE:Leap 16.0 / ofono

Package

Name
ofono
Purl
pkg:rpm/opensuse/ofono&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.19-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "ofono":  "2.19-bp160.1.1",
            "ofono-devel":  "2.19-bp160.1.1",
            "ofono-tests":  "2.19-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21154-1.json"