CVE-2026-75895 PUBLISHED

Out of bounds read at smpp34_unpack()

Assigner: redhat-cnalr
Reserved: 18.08.2026 Published: 18.09.2026 Updated: 18.09.2026

In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to memory corruption.

Product Status

Vendor Osmocom
Product libsmpp34
Versions Default: unknown
  • affected from 1.10.0 to 1.14.5 (excl.)

Credits

  • Nikolas Null "n0k0" - Security Researcher at mnemonic finder

References

Problem Types

  • CWE-125 Out-of-bounds read CWE