The MMS server connection handler contains a flaw in its processing of
BER-encoded request data. When an MMS confirmed request PDU containing
an extended BER tag is received over an established session, the decoder
may advance its internal buffer incorrectly due to a missing bounds
check. This results in a one byte heap out-of-bounds read and causes the
MMS service process to terminate, leading to a denial-of-service
condition.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-30 23:16
Updated : 2026-09-08 19:30
NVD link : CVE-2026-66349
Mitre link : CVE-2026-66349
CVE.ORG link : CVE-2026-66349
JSON object : View
Products Affected
No product.
CWE
CWE-125
Out-of-bounds Read
