debian · CVE-2023-4232

Quick triage

Priority: not yet assigned Published: Updated: Sat, 27 Jun 2026 00:59:23 GMT

View at Official debian advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2023-4232 not yet assigned priority: Debian including 1 source packages (ofono), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 3, open 2.

Description:

A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_status_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_status_report().

cvelogic Threat Intelligence