CVE-2026-75895: Osmocom LIBSMPP34

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to memory corruption.

Affected products

  • Osmocom LIBSMPP34: from 1.10.0, before 1.14.5 (fixed in 1.14.5)

Published 2026-09-18. Last modified 2026-09-30.