Description
In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg()  function via IPA frame lengths.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Heap-based buffer overflow leading to potential arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

In the osmo-bsc Base Station Controller, the function ipaccess_proxy_read_msg() processes IPA frame lengths without proper bounds checking. When an attacker supplies a crafted IPA frame, the routine writes beyond the allocated heap buffer, which can corrupt adjacent memory and potentially allow execution of arbitrary code. This is a classic heap buffer overflow (CWE‑122) that can compromise confidentiality, integrity, and availability if successfully exploited.

Affected Systems

All Osmocom osmo-bsc releases from version 1.0.1 up to and including 1.14.1 are vulnerable. The issue was introduced in the 1.0.1 release and persists through the 1.14.1 release. The specific version tracking provided by the CNA confirms the affected range. No other Osmocom osmo-bsc releases are known to be affected.

Risk and Exploitability

The EPSS score of 0.00141 (less than 1%) indicates a very low exploitation probability, despite the CVSS score of 7.5 which signals high severity when an attacker can control IPA frame length. The primary attack vector is remote: an entity with the ability to send IPA frames to the base station controller may trigger the overflow. The absence of authentication in the provided description suggests that an attacker could use a compromised handset or rogue device connected to the network, making the risk significant for operational deployments.

Generated by OpenCVE AI on September 21, 2026 at 21:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch referenced in commit 2852a03c153cd9418c2a86d0b2193ac41169dbb7 to the osmo-bsc source, then rebuild and deploy the updated binary.
  • Upgrade to any osmo-bsc version newer than 1.14.1 or to the latest stable release where the patch is incorporated.
  • Restrict access to the IPA interface by configuring firewall rules or VLAN segmentation so that only trusted network elements can send IPA messages.
  • Implement monitoring for abnormal IPA frame lengths or repeated buffer overflows after the patch, and enforce logging of received IPA messages.

Generated by OpenCVE AI on September 21, 2026 at 21:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Osmocom
Osmocom osmo-bsc
Vendors & Products Osmocom
Osmocom osmo-bsc

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg()  function via IPA frame lengths.
Title Heap based buffer overflow at ipaccess_proxy_read_msg()
Weaknesses CWE-122
References

Subscriptions

Osmocom Osmo-bsc
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat-cnalr

Published:

Updated: 2026-09-21T18:16:09.346Z

Reserved: 2026-08-18T14:04:08.775Z

Link: CVE-2026-75893

cve-icon Vulnrichment

Updated: 2026-09-21T18:16:05.577Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T19:16:45.860

Modified: 2026-09-21T19:17:09.910

Link: CVE-2026-75893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T21:15:14Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow