Package: release.debian.org
Severity: normal
Tags: trixie
User: [email protected]
Usertags: pu


The attached debdiff for libsmpp34 fixes CVE-2026-75895 in Trixie. This CVE is marked as no-dsa by the security team. Nevertheless CISA-ADP evaluated a score of 7.5 for this CVE, which is categorized as "high".

The fixed version (1.14.6-1) has been uploaded to unstable some day ago and nobody complained yet.

   Thorsten
diff -Nru libsmpp34-1.14.4/debian/changelog libsmpp34-1.14.4/debian/changelog
--- libsmpp34-1.14.4/debian/changelog   2024-07-06 00:57:04.000000000 +0200
+++ libsmpp34-1.14.4/debian/changelog   2026-09-25 18:57:04.000000000 +0200
@@ -1,3 +1,10 @@
+libsmpp34 (1.14.4-1+deb13u1) trixie; urgency=high
+
+  * CVE-2026-75895 (Closes: #1148557)
+    out of bound read
+
+ -- Thorsten Alteholz <[email protected]>  Fri, 25 Sep 2026 18:57:04 +0200
+
 libsmpp34 (1.14.4-1) unstable; urgency=medium
 
   * New upstream release. (Closes: #1073344)
diff -Nru libsmpp34-1.14.4/debian/patches/CVE-2026-75895.patch 
libsmpp34-1.14.4/debian/patches/CVE-2026-75895.patch
--- libsmpp34-1.14.4/debian/patches/CVE-2026-75895.patch        1970-01-01 
01:00:00.000000000 +0100
+++ libsmpp34-1.14.4/debian/patches/CVE-2026-75895.patch        2026-09-25 
18:57:04.000000000 +0200
@@ -0,0 +1,40 @@
+From af0e2912057551dab97bbe26e6a41f18a75f3bbb Mon Sep 17 00:00:00 2001
+From: n0k0 <[email protected]>
+Date: Thu, 25 Jun 2026 10:20:37 +0200
+Subject: smpp34_unpack: bound C_OCTET scan with strnlen()
+
+The C_OCTET macro runs strlen() on the attacker-controlled wire buffer
+before any bounds check. SMPP PDUs are decoded straight out of a buffer
+sized exactly to the wire command_length with no trailing NUL, so a
+C-Octet-String field that runs to the end of the buffer without a
+terminator makes strlen() read past the end of the allocation (out of
+bounds heap read), and the post-hoc "lenval > left" check runs only
+after the over-read has already happened.
+
+Scan with strnlen(aux, left) so the read can never go past the remaining
+buffer; if no terminator is found within 'left' bytes, lenval becomes
+left + 1 and the existing length check rejects the PDU.
+
+This issue has been assigned the CVE candidate identifier
+CAN-2026-2051038.
+
+Change-Id: Ie87b16cad0dbdc8ea8397c1b065b8545f23ac814
+---
+ src/smpp34_unpack.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/smpp34_unpack.c b/src/smpp34_unpack.c
+index ec73d35..47d34ba 100644
+--- a/src/smpp34_unpack.c
++++ b/src/smpp34_unpack.c
+@@ -127,7 +127,7 @@ smpp34_unpack(uint32_t type, void* tt, const uint8_t 
*ptrBuf, int ptrLen)
+ 
+ 
+ #define C_OCTET( inst, par, size ){\
+-    lenval = strlen( (char*) aux ) + 1;\
++      lenval = strnlen((char *)aux, left) + 1;\
+     if( lenval > left ){\
+         PUTLOG("[len(%s):%d(%s)]", par, lenval, \
+                                       "Value length exceed buffer length");\
+-- 
+cgit v1.2.3
diff -Nru libsmpp34-1.14.4/debian/patches/series 
libsmpp34-1.14.4/debian/patches/series
--- libsmpp34-1.14.4/debian/patches/series      2024-07-06 00:55:06.000000000 
+0200
+++ libsmpp34-1.14.4/debian/patches/series      2026-09-25 18:57:04.000000000 
+0200
@@ -1 +1 @@
-#applied upstream: fixed_typo.patch
+CVE-2026-75895.patch

Reply via email to