CVE-2026-20449: Buffer Overflow
In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01760138; Issue ID: MSV-6148.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20449?
CVE-2026-20449 is considered a critical vulnerability due to its potential to cause a system crash and remote denial of service.
How do I fix CVE-2026-20449?
To fix CVE-2026-20449, ensure that you apply the latest security patch provided by your modem's manufacturer.
What are the consequences of exploiting CVE-2026-20449?
Exploiting CVE-2026-20449 can lead to a remote denial of service, causing affected systems to crash when connected to a rogue base station.
Is user interaction required to exploit CVE-2026-20449?
No, user interaction is not required for the exploitation of CVE-2026-20449, making it particularly dangerous.
What type of devices are affected by CVE-2026-20449?
CVE-2026-20449 affects devices utilizing the Modem software, specifically those connecting to rogue base stations.