|
|
Log in / Subscribe / Register

SUSE alert openSUSE-SU-2026:21154-1 (ofono)

From:  null@suse.de
To:  security-announce@lists.opensuse.org
Subject:  openSUSE-SU-2026:21154-1: important: Security update for ofono
Date:  Tue, 30 Jun 2026 09:48:39 +0200
Message-ID:  <20260630074839.3BBA0FF8C@maintenance.suse.de>
Archive-link:  Article

openSUSE security update: security update for ofono ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21154-1 Rating: important References: * bsc#1218292 * bsc#1218293 * bsc#1218294 * bsc#1218295 * bsc#1218296 * bsc#1228903 * bsc#1228904 * bsc#1228905 * bsc#1228906 * bsc#1228907 * bsc#1228908 * bsc#1228910 * bsc#1228913 * bsc#1228914 * bsc#1228916 * bsc#1228917 Cross-References: * CVE-2023-2794 * CVE-2023-4232 * CVE-2023-4233 * CVE-2023-4234 * CVE-2023-4235 * CVE-2024-7537 * CVE-2024-7538 * CVE-2024-7539 * CVE-2024-7540 * CVE-2024-7541 * CVE-2024-7542 * CVE-2024-7543 * CVE-2024-7544 * CVE-2024-7545 * CVE-2024-7546 * CVE-2024-7547 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 16 vulnerabilities and has 16 bug fixes can now be installed. Description: This update for ofono fixes the following issues: Changes in ofono: - Reference the tracking bugs for the SMS/STK/USSD decoder security fixes applied upstream across the 2.14-2.17 updates: * SMS decoder stack buffer overflows: CVE-2023-2794 (boo#1218292), CVE-2023-4232 (boo#1218293), CVE-2023-4233 (boo#1218294), CVE-2023-4234 (boo#1218295), CVE-2023-4235 (boo#1218296) * SMS PDU / message-list parsing overflows and OOB read: CVE-2024-7537 (boo#1228903), CVE-2024-7547 (boo#1228917) * AT-command / USSD response parsing overflows: CVE-2024-7538 (boo#1228904), CVE-2024-7539 (boo#1228905) * Uninitialized-memory information disclosure: CVE-2024-7540 (boo#1228906), CVE-2024-7541 (boo#1228907), CVE-2024-7542 (boo#1228908) * STK command PDU heap overflows: CVE-2024-7543 (boo#1228910), CVE-2024-7544 (boo#1228913), CVE-2024-7545 (boo#1228914), CVE-2024-7546 (boo#1228916) - Update to version 2.19 * Add support for PPP reset workaround for SIM7100 modem. * Add support for Qualcomm RAW-IP only devices. - Update to version 2.18 * Fix issue with QMI and handling SMS message acknowledgement. * Fix issue with handling SIM7100 modem ready detection. * Add support for forbidden operator list. - Update to version 2.17 * Fix issue with SMS and possible buffer overflow. - Update to version 2.16 * Add support for QMI service request rate limiting. - Update to version 2.15 * Fix issue with SMS and uninitialized buffers. * Fix issue with USSD and uninitialized buffers. * Add support for the Test Anything Protocol. - Update to version 2.14 * Fix issue with STK and buffer length checks. * Fix issue with SMS and buffer length checks. * Fix issue with QMI and handling RAT detection. * Fix issue with QMI and handling call forwarding. * Add support for handling MHI network interfaces. - Update to version 2.13 * Add support for handling QMI PIN and Lock methods. * Add support for handling QMI WWAN interfaces. * Add support for handling RMNet interfaces. - Update to version 2.12 * Fix issue with access technology reporting. * Fix issue with detecting Phonet devices. - Update to version 2.11 * Add support for SIMCom A7672E-FASE modem. * Add support for Quectel EG916Q-GL modem. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-349=1 Package List: - openSUSE Leap 16.0: ofono-2.19-bp160.1.1 ofono-devel-2.19-bp160.1.1 ofono-tests-2.19-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2023-2794.html * https://www.suse.com/security/cve/CVE-2023-4232.html * https://www.suse.com/security/cve/CVE-2023-4233.html * https://www.suse.com/security/cve/CVE-2023-4234.html * https://www.suse.com/security/cve/CVE-2023-4235.html * https://www.suse.com/security/cve/CVE-2024-7537.html * https://www.suse.com/security/cve/CVE-2024-7538.html * https://www.suse.com/security/cve/CVE-2024-7539.html * https://www.suse.com/security/cve/CVE-2024-7540.html * https://www.suse.com/security/cve/CVE-2024-7541.html * https://www.suse.com/security/cve/CVE-2024-7542.html * https://www.suse.com/security/cve/CVE-2024-7543.html * https://www.suse.com/security/cve/CVE-2024-7544.html * https://www.suse.com/security/cve/CVE-2024-7545.html * https://www.suse.com/security/cve/CVE-2024-7546.html * https://www.suse.com/security/cve/CVE-2024-7547.html


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds