CVE-2024-7543
published 2024-08-06CVE-2024-7543: oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected…
PriorityP348high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
21.7th percentile
oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability.
The specific flaw exists within the parsing of STK command PDUs. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-23456.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ofono | < ofono 2.14-1 (forky) | ofono 2.14-1 (forky) |
| ofono | ofono | — | — |
| ofono | ofono | >= 0 < 2.14-1 | 2.14-1 |
| ofono | ofono | >= 0 < 2.14-1 | 2.14-1 |
| ofono_project | ofono | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
oFono vulnerabilities
vendor_ubuntu·2026-04-16·CVSS 7.8
CVE-2024-7540 [HIGH] oFono vulnerabilities
Title: oFono vulnerabilities
Summary: oFono could be made to crash if it received specially crafted input.
It was discovered that oFono incorrectly handled crafted responses
from AT commands. An attacker could possibly use this issue to crash
the program, resulting in a denial of service or arbitrary code
execution. (CVE-2024-7538, CVE-2024-7539, CVE-2024-7540, CVE-2024-7541,
CVE-2024-7542)
Lucas Leong discovered that oFono incorrectly handled crafted input.
An attacker could possibly use this issue to crash the program,
resulting in a denial of service or arbitrary code execution.
(CVE-2024-7543, CVE-2024-7544, CVE-2024-7545, CVE-2024-7546,
CVE-2024-7547)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
kernel: ipv6: fix possible race in __fib6_drop_pcpu_from()
vendor_redhat·2024-07-12·CVSS 4.7
CVE-2024-40905 [MEDIUM] CWE-476 kernel: ipv6: fix possible race in __fib6_drop_pcpu_from()
kernel: ipv6: fix possible race in __fib6_drop_pcpu_from()
In the Linux kernel, the following vulnerability has been resolved:
ipv6: fix possible race in __fib6_drop_pcpu_from()
syzbot found a race in __fib6_drop_pcpu_from() [1]
If compiler reads more than once (*ppcpu_rt),
second read could read NULL, if another cpu clears
the value in rt6_get_pcpu_route().
Add a READ_ONCE() to prevent this race.
Also add rcu_read_lock()/rcu_read_unlock() because
we rely on RCU protection while dereferencing pcpu_rt.
[1]
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000012: 0000 [#1] PREEMPT SMP KASAN PTI
KASAN: null-ptr-deref in range [0x0000000000000090-0x0000000000000097]
CPU: 0 PID: 7543 Comm: kworker/u8:17 Not tainted 6.10.0-rc1-syzkaller-00013-g2bfcfd584ff5 #0
Hardw
Debian
CVE-2024-7543: ofono - oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. ...
vendor_debian·2024·CVSS 7.8
CVE-2024-7543 [HIGH] CVE-2024-7543: ofono - oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. ...
oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw exists within the parsing of STK command PDUs. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-23456.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.14-1)
sid: resolved (fixed in 2.14-1)
trixie: resolved (fixed in 2.14-1)
VulDB
oFono 2.3 SimToolKit heap-based overflow (ZDI-24-1083 / Nessus ID 307010)
vuldb·2026-04-17·CVSS 7.8
CVE-2024-7543 [HIGH] oFono 2.3 SimToolKit heap-based overflow (ZDI-24-1083 / Nessus ID 307010)
A vulnerability marked as critical has been reported in oFono 2.3. Affected by this vulnerability is an unknown functionality of the component SimToolKit. Performing a manipulation results in heap-based buffer overflow.
This vulnerability is cataloged as CVE-2024-7543. The attack must be initiated from a local position. There is no exploit available.
GHSA
GHSA-7fjm-wq66-2552: oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability
ghsa_unreviewed·2024-08-06
CVE-2024-7543 [HIGH] CWE-122 GHSA-7fjm-wq66-2552: oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability
oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability.
The specific flaw exists within the parsing of STK command PDUs. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-23456.
OSV
CVE-2024-7543: oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability
osv·2024-08-06·CVSS 7.8
CVE-2024-7543 [HIGH] CVE-2024-7543: oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability
oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw exists within the parsing of STK command PDUs. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-23456.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-06
Published