Bugzilla – Bug 1223697
VUL-0: CVE-2023-26793: libmodbus: heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c.
Last modified: 2024-06-11 22:17:50 UTC
libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-26793 https://www.cve.org/CVERecord?id=CVE-2023-26793 https://github.com/stephane/libmodbus/issues/683
No information upstream Tracking as affected: - openSUSE:Backports:SLE-15-SP5/libmodbus 3.1.10 - openSUSE:Backports:SLE-15-SP6/libmodbus 3.1.10 - openSUSE:Factory/libmodbus 3.1.10
However it is more than a year old report, there is apparently no fix yet. https://nvd.nist.gov/vuln/detail/CVE-2023-26793 This vulnerability is currently awaiting analysis.
Checking the upstream, there is no fix. The upstream issue has no progress. Is it serious enough to start a research? Note that we have no Modbus testing hardware.