Entry Thumbnail

CVE-2025-20678: Mediatek Baseband Unbounded Recursion Leading to Stack Overflow During Handling XML Payload

An attacker sending a malformed SIP message over VoLTE to a device with a Mediatek baseband can trigger the vulnerability described here. This report describes an unbounded recursion issue, which leads to stack overflow. (Note: the issue is stack overflow not stack **buffer** overtflow, i.e. an out-of-bounds write beyond a […]

Posted by
Entry Thumbnail

CVE-2023-32887: Mediatek Baseband Unbounded Recursion Leading to Stack Overflow During Handling SIP Comments

An attacker sending a malformed SIP message over VoLTE to a device with a Mediatek baseband can trigger the vulnerability described here. The impact is unbounded recursion based stack overflow in the baseband, triggered by malformed VoLTE message such as SIP INVITE or MESSAGE request. The vulnerability described in this […]

Posted by