CVE-2023-2794: Ofono: sms decoder stack-based buffer overflow remote code execution vulnerability within the decode_deliver() function

Published Dec 20, 2023
·
Updated

A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decodedeliver() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decodesubmit(), but it was forgotten in decodedeliver().

Other sources

ofono is a Open Source Telephony on Linux stack overflow bug is triggered within the decodedeliver() function during SMS decoding here assumed that the attack scenario is accessible from a compromised modem or possibily accessible from a malicious base station or just SMS

there is a bound check for this memcpy length in decodesubmit(), but they forgot it in decodedeliver() partial code path is here - atcmtnotify() - ofonosmsdelivernotify() - smsdecode() - decodedeliver()

~~~C++ static gboolean decodedeliver(const unsigned char pdu, int len, struct sms out) { int offset = 0; int expected; unsigned char octet;

out->type = SMSTYPEDELIVER;

if (!nextoctet(pdu, len, &offset, &octet)) return FALSE;

out->deliver.mms = !isbitset(octet, 2); out->deliver.sri = isbitset(octet, 5); out->deliver.udhi = isbitset(octet, 6); out->deliver.rp = isbitset(octet, 7);

if (!smsdecodeaddressfield(pdu, len, &offset, FALSE, &out->deliver.oaddr)) return FALSE;

if (!nextoctet(pdu, len, &offset, &out->deliver.pid)) return FALSE;

if (!nextoctet(pdu, len, &offset, &out->deliver.dcs)) return FALSE;

if (!smsdecodescts(pdu, len, &offset, &out->deliver.scts)) return FALSE;

if (!nextoctet(pdu, len, &offset, &out->deliver.udl)) return FALSE;

expected = smsudlinbytes(out->deliver.udl, out->deliver.dcs);

if ((len - offset) < expected) return FALSE;

memcpy(out->deliver.ud, pdu + offset, expected); // overflow here, expected is from SMS PDU

return TRUE; } ~~~

ASAN report ================================================================= ==116975==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x7ffcf34201bc at pc 0x7f027e049846 bp 0x7ffcf341fea0 sp 0x7ffcf341f648 WRITE of size 203 at 0x7ffcf34201bc thread T0 #0 0x7f027e049845 in interceptormemcpy ../../../../src/libsanitizer/sanitizercommon/sanitizercommoninterceptors.inc:827 #1 0x556caadab9e3 in decodedeliver src/smsutil.c:782 #2 0x556caadb14bf in smsdecode src/smsutil.c:1574 #3 0x556caad4d08d in main src/main.c:225 #4 0x7f027da2350f in libcstartcallmain ../sysdeps/nptl/libcstartcallmain.h:58 #5 0x7f027da235c8 in libcstartmainimpl ../csu/libc-start.c:381 #6 0x556caaaec274 in start (/root/ofono/src/ofonod+0x12b274)

Address 0x7ffcf34201bc is located in stack of thread T0 at offset 316 in frame #0 0x556caad4cedd in main src/main.c:205

This frame has 1 object(s): [48, 316) 'sms1' (line 212) <== Memory access at offset 316 overflows this variable HINT: this may be a false positive if your program uses some custom stack unwind mechanism, swapcontext or vfork (longjmp and C++ exceptions are supported) SUMMARY: AddressSanitizer: stack-buffer-overflow ../../../../src/libsanitizer/sanitizercommon/sanitizercommoninterceptors.inc:827 in interceptormemcpy Shadow bytes around the buggy address: 0x10001e67bfe0: f1 f1 01 f2 04 f3 f3 f3 00 00 00 00 00 00 00 00 0x10001e67bff0: 00 00 00 00 00 00 00 00 f1 f1 f1 f1 04 f3 f3 f3 0x10001e67c000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x10001e67c010: f1 f1 f1 f1 f1 f1 00 00 00 00 00 00 00 00 00 00 0x10001e67c020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 =>0x10001e67c030: 00 00 00 00 00 00 00[04]f3 f3 f3 f3 f3 f3 f3 f3 0x10001e67c040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x10001e67c050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x10001e67c060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x10001e67c070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x10001e67c080: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 Shadow byte legend (one shadow byte represents 8 application bytes): Addressable: 00 Partially addressable: 01 02 03 04 05 06 07 Heap left redzone: fa Freed heap region: fd Stack left redzone: f1 Stack mid redzone: f2 Stack right redzone: f3 Stack after return: f5 Stack use after scope: f8 Global redzone: f9 Global init order: f6 Poisoned by user: f7 Container overflow: fc Array cookie: ac Intra object redzone: bb ASan internal: fe Left alloca redzone: ca Right alloca redzone: cb ==116975==ABORTING

Red Hat

Affected Software

5 affected componentsFixes available
redhat/ofono<2.1
2.1
debian/ofono<=1.31-3
2.12-1
Ofono Project Ofono<2.5
Fedoraproject Fedora=39
Fedoraproject Fedora=40

Event History

Apr 10, 2024
CVE Published
via MITRE·10:15 AM
Data Sourced
via MITRE·10:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
Affected Software
Dec 10, 2024
Data Sourced
via Launchpad·01:10 AM
Description
Dec 14, 2024
Data Sourced
via Ubuntu·01:10 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2023-2794?

CVE-2023-2794 is considered to have a high severity due to the potential for remote exploitation through SMS.

2

How do I fix CVE-2023-2794?

To fix CVE-2023-2794, update the ofono package to version 2.1 for Red Hat or 2.12-1 for Debian.

3

What systems are affected by CVE-2023-2794?

CVE-2023-2794 affects the ofono package on Red Hat and Debian systems that have versions below the patched versions.

4

What type of vulnerability is CVE-2023-2794?

CVE-2023-2794 is a stack overflow vulnerability triggered during SMS decoding within the decode_deliver() function.

5

What attack vectors are associated with CVE-2023-2794?

CVE-2023-2794 can be exploited through a compromised modem, a malicious base station, or by sending malicious SMS.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203