{"id":"CVE-2026-75893","title":"In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg()  function via IPA frame lengths.","summary":"In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg()  function via IPA frame lengths.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-122"],"vendor":"Osmocom","product":"osmo-bsc","affected":["osmo-bsc >= 1.0.1 < 1.14.1"],"published":"2026-09-18","updated":"2026-09-21","sourceUpdated":"2026-09-21T19:17:09.910","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-75893","references":[{"url":"https://cgit.osmocom.org/osmo-bsc/commit/?id=2852a03c153cd9418c2a86d0b2193ac41169dbb7","label":"74b3a70d-cca6-4d34-9789-e83b222ae3be"}],"tags":["nvd","cve.org"],"epss":0.00267,"epssPercentile":0.19067,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-21T18:15:49.133561Z"},"ingestedAt":"2026-09-18T18:47:53.272Z","slug":"CVE-2026-75893","body":"## Overview\n\nIn osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg()  function via IPA frame lengths.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":208731,"id":"CVE-2026-75893","ts":1790016709869,"field":"cvss","old":null,"new":"7.5"},{"seq":208730,"id":"CVE-2026-75893","ts":1790016709869,"field":"severity","old":"none","new":"high"}]}