Description
In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to memory corruption.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption from an out-of-bounds read
Action: Apply patch
AI Analysis

Impact

The vulnerability lies in smpp34_unpack() where an out-of-bounds read can corrupt memory when parsing SMPP PDUs. The description indicates that malformed or oversized PDUs trigger the issue. While the description does not explicitly state the outcome, it is inferred that the corruption could result in a process crash and potentially allow unintended code execution depending on the surrounding memory layout.

Affected Systems

The flaw affects Osmocom libsmpp34 across versions 0.1.0 to 1.8.0 inclusive. Systems that rely on this library to process SMPP traffic, such as telecommunications infrastructure or VoIP gateways implementing OSMO_SL functions, are at risk unless they run a later revision.

Risk and Exploitability

The defect is an out-of-bounds read; an attacker may exploit it by sending crafted SMPP PDUs to a vulnerable instance. The description does not mention authentication requirements, so it is inferred that no special credentials are needed. The CVSS score of 7.5 indicates a high severity, while the EPSS score of <1% suggests a low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog and no public exploits are reported.

Generated by OpenCVE AI on September 21, 2026 at 21:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade libsmpp34 to a version newer than 1.8.0 or apply the patch provided in commit af0e2912057551dab97bbe26e6a41f18a75f3bbb
  • Restart services that use libsmpp34 after the upgrade to clear any corrupted state
  • Validate incoming SMPP PDUs against size limits or implement additional input sanitization to prevent malformed packets from reaching the library

Generated by OpenCVE AI on September 21, 2026 at 21:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4804-1 libsmpp34 security update
History

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
References

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Osmocom
Osmocom libsmpp34
Vendors & Products Osmocom
Osmocom libsmpp34

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to memory corruption.
Title Out of bounds read at smpp34_unpack()
Weaknesses CWE-125
References

Subscriptions

Osmocom Libsmpp34
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat-cnalr

Published:

Updated: 2026-09-30T17:07:29.973Z

Reserved: 2026-08-18T14:04:08.775Z

Link: CVE-2026-75895

cve-icon Vulnrichment

Updated: 2026-09-30T17:07:29.973Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:21.487

Modified: 2026-09-30T18:18:40.390

Link: CVE-2026-75895

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T21:15:14Z

Weaknesses