Bug 2540006 (CVE-2026-95622) - CVE-2026-95622 ModemManager: ModemManager: Reachable assertion in Cell Broadcast encoding parse causes denial of service
Summary: CVE-2026-95622 ModemManager: ModemManager: Reachable assertion in Cell Broadc...
Keywords:
Status: NEW
Alias: CVE-2026-95622
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2540008
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-24 10:33 UTC by OSIDB Bzimport
Modified: 2026-09-24 10:42 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-24 10:33:46 UTC
A flaw was found in ModemManager. When parsing a Cell Broadcast Message, some 3GPP data-coding-scheme values (8-bit and reserved character sets) are not handled. The process hits a reachable assertion and aborts. An attacker who can deliver a crafted Cell Broadcast PDU over the radio network, or via a modem AT channel, can cause ModemManager to exit. Repeated aborts can exhaust systemd's default start limit and leave the service failed.


Note You need to log in before you can comment on or make changes to this bug.