CVE-2026-75893 PUBLISHED

Heap based buffer overflow at ipaccess_proxy_read_msg()

Assigner: redhat-cnalr
Reserved: 18.08.2026 Published: 18.09.2026 Updated: 18.09.2026

In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg()  function via IPA frame lengths.

Product Status

Vendor Osmocom
Product osmo-bsc
Versions Default: unknown
  • affected from 1.0.1 to 1.14.1 (excl.)

Credits

  • Nikolas Null "n0k0" - Security Researcher at mnemonic finder

References

Problem Types

  • CWE-122 Heap-based buffer overflow CWE