{"id":"openSUSE-SU-2026:21154-1","summary":"Security update for ofono","details":"This update for ofono fixes the following issues:\n\nChanges in ofono:\n\n- Reference the tracking bugs for the SMS/STK/USSD decoder security\n  fixes applied upstream across the 2.14-2.17 updates:\n  * SMS decoder stack buffer overflows: CVE-2023-2794 (boo#1218292),\n    CVE-2023-4232 (boo#1218293), CVE-2023-4233 (boo#1218294),\n    CVE-2023-4234 (boo#1218295), CVE-2023-4235 (boo#1218296)\n  * SMS PDU / message-list parsing overflows and OOB read:\n    CVE-2024-7537 (boo#1228903), CVE-2024-7547 (boo#1228917)\n  * AT-command / USSD response parsing overflows: CVE-2024-7538\n    (boo#1228904), CVE-2024-7539 (boo#1228905)\n  * Uninitialized-memory information disclosure: CVE-2024-7540\n    (boo#1228906), CVE-2024-7541 (boo#1228907), CVE-2024-7542\n    (boo#1228908)\n  * STK command PDU heap overflows: CVE-2024-7543 (boo#1228910),\n    CVE-2024-7544 (boo#1228913), CVE-2024-7545 (boo#1228914),\n    CVE-2024-7546 (boo#1228916)\n\n- Update to version 2.19\n  * Add support for PPP reset workaround for SIM7100 modem.\n  * Add support for Qualcomm RAW-IP only devices.\n\n- Update to version 2.18\n  * Fix issue with QMI and handling SMS message acknowledgement.\n  * Fix issue with handling SIM7100 modem ready detection.\n  * Add support for forbidden operator list.\n\n- Update to version 2.17\n  * Fix issue with SMS and possible buffer overflow.\n\n- Update to version 2.16\n  * Add support for QMI service request rate limiting.\n\n- Update to version 2.15\n  * Fix issue with SMS and uninitialized buffers.\n  * Fix issue with USSD and uninitialized buffers.\n  * Add support for the Test Anything Protocol.\n\n- Update to version 2.14\n  * Fix issue with STK and buffer length checks.\n  * Fix issue with SMS and buffer length checks.\n  * Fix issue with QMI and handling RAT detection.\n  * Fix issue with QMI and handling call forwarding.\n  * Add support for handling MHI network interfaces.\n\n- Update to version 2.13\n  * Add support for handling QMI PIN and Lock methods.\n  * Add support for handling QMI WWAN interfaces.\n  * Add support for handling RMNet interfaces.\n\n- Update to version 2.12\n  * Fix issue with access technology reporting.\n  * Fix issue with detecting Phonet devices.\n\n- Update to version 2.11\n  * Add support for SIMCom A7672E-FASE modem.\n  * Add support for Quectel EG916Q-GL modem.\n","modified":"2026-06-30T18:24:53.677240375Z","published":"2026-06-23T13:07:52Z","related":["CVE-2023-2794","CVE-2023-4232","CVE-2023-4233","CVE-2023-4234","CVE-2023-4235","CVE-2024-7537","CVE-2024-7538","CVE-2024-7539","CVE-2024-7540","CVE-2024-7541","CVE-2024-7542","CVE-2024-7543","CVE-2024-7544","CVE-2024-7545","CVE-2024-7546","CVE-2024-7547"],"upstream":["CVE-2023-2794","CVE-2023-4232","CVE-2023-4233","CVE-2023-4234","CVE-2023-4235","CVE-2024-7537","CVE-2024-7538","CVE-2024-7539","CVE-2024-7540","CVE-2024-7541","CVE-2024-7542","CVE-2024-7543","CVE-2024-7544","CVE-2024-7545","CVE-2024-7546","CVE-2024-7547"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218292"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218293"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218294"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218295"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218296"},{"type":"REPORT","url":"https://bugzilla.suse.com/1228903"},{"type":"REPORT","url":"https://bugzilla.suse.com/1228904"},{"type":"REPORT","url":"https://bugzilla.suse.com/1228905"},{"type":"REPORT","url":"https://bugzilla.suse.com/1228906"},{"type":"REPORT","url":"https://bugzilla.suse.com/1228907"},{"type":"REPORT","url":"https://bugzilla.suse.com/1228908"},{"type":"REPORT","url":"https://bugzilla.suse.com/1228910"},{"type":"REPORT","url":"https://bugzilla.suse.com/1228913"},{"type":"REPORT","url":"https://bugzilla.suse.com/1228914"},{"type":"REPORT","url":"https://bugzilla.suse.com/1228916"},{"type":"REPORT","url":"https://bugzilla.suse.com/1228917"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-2794"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4232"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4233"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4234"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4235"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7537"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7538"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7539"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7540"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7541"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7542"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7543"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7544"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7545"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7546"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7547"}],"affected":[{"package":{"name":"ofono","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/ofono&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.19-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"ofono":"2.19-bp160.1.1","ofono-devel":"2.19-bp160.1.1","ofono-tests":"2.19-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21154-1.json"}}],"schema_version":"1.7.5"}