Package: release.debian.org Severity: normal Tags: trixie User: [email protected] Usertags: pu
The attached debdiff for libsmpp34 fixes CVE-2026-75895 in Trixie. This CVE is marked as no-dsa by the security team. Nevertheless CISA-ADP evaluated a score of 7.5 for this CVE, which is categorized as "high".
The fixed version (1.14.6-1) has been uploaded to unstable some day ago and nobody complained yet.
Thorsten
diff -Nru libsmpp34-1.14.4/debian/changelog libsmpp34-1.14.4/debian/changelog --- libsmpp34-1.14.4/debian/changelog 2024-07-06 00:57:04.000000000 +0200 +++ libsmpp34-1.14.4/debian/changelog 2026-09-25 18:57:04.000000000 +0200 @@ -1,3 +1,10 @@ +libsmpp34 (1.14.4-1+deb13u1) trixie; urgency=high + + * CVE-2026-75895 (Closes: #1148557) + out of bound read + + -- Thorsten Alteholz <[email protected]> Fri, 25 Sep 2026 18:57:04 +0200 + libsmpp34 (1.14.4-1) unstable; urgency=medium * New upstream release. (Closes: #1073344) diff -Nru libsmpp34-1.14.4/debian/patches/CVE-2026-75895.patch libsmpp34-1.14.4/debian/patches/CVE-2026-75895.patch --- libsmpp34-1.14.4/debian/patches/CVE-2026-75895.patch 1970-01-01 01:00:00.000000000 +0100 +++ libsmpp34-1.14.4/debian/patches/CVE-2026-75895.patch 2026-09-25 18:57:04.000000000 +0200 @@ -0,0 +1,40 @@ +From af0e2912057551dab97bbe26e6a41f18a75f3bbb Mon Sep 17 00:00:00 2001 +From: n0k0 <[email protected]> +Date: Thu, 25 Jun 2026 10:20:37 +0200 +Subject: smpp34_unpack: bound C_OCTET scan with strnlen() + +The C_OCTET macro runs strlen() on the attacker-controlled wire buffer +before any bounds check. SMPP PDUs are decoded straight out of a buffer +sized exactly to the wire command_length with no trailing NUL, so a +C-Octet-String field that runs to the end of the buffer without a +terminator makes strlen() read past the end of the allocation (out of +bounds heap read), and the post-hoc "lenval > left" check runs only +after the over-read has already happened. + +Scan with strnlen(aux, left) so the read can never go past the remaining +buffer; if no terminator is found within 'left' bytes, lenval becomes +left + 1 and the existing length check rejects the PDU. + +This issue has been assigned the CVE candidate identifier +CAN-2026-2051038. + +Change-Id: Ie87b16cad0dbdc8ea8397c1b065b8545f23ac814 +--- + src/smpp34_unpack.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/smpp34_unpack.c b/src/smpp34_unpack.c +index ec73d35..47d34ba 100644 +--- a/src/smpp34_unpack.c ++++ b/src/smpp34_unpack.c +@@ -127,7 +127,7 @@ smpp34_unpack(uint32_t type, void* tt, const uint8_t *ptrBuf, int ptrLen) + + + #define C_OCTET( inst, par, size ){\ +- lenval = strlen( (char*) aux ) + 1;\ ++ lenval = strnlen((char *)aux, left) + 1;\ + if( lenval > left ){\ + PUTLOG("[len(%s):%d(%s)]", par, lenval, \ + "Value length exceed buffer length");\ +-- +cgit v1.2.3 diff -Nru libsmpp34-1.14.4/debian/patches/series libsmpp34-1.14.4/debian/patches/series --- libsmpp34-1.14.4/debian/patches/series 2024-07-06 00:55:06.000000000 +0200 +++ libsmpp34-1.14.4/debian/patches/series 2026-09-25 18:57:04.000000000 +0200 @@ -1 +1 @@ -#applied upstream: fixed_typo.patch +CVE-2026-75895.patch

