Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package libosmocore for openSUSE:Factory 
checked in at 2026-08-21 17:01:27
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/libosmocore (Old)
 and      /work/SRC/openSUSE:Factory/.libosmocore.new.1258 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "libosmocore"

Fri Aug 21 17:01:27 2026 rev:42 rq:1372814 version:1.14.2

Changes:
--------
--- /work/SRC/openSUSE:Factory/libosmocore/libosmocore.changes  2026-07-23 
23:34:59.404205584 +0200
+++ /work/SRC/openSUSE:Factory/.libosmocore.new.1258/libosmocore.changes        
2026-08-21 17:02:50.689288740 +0200
@@ -1,0 +2,12 @@
+Fri Aug 21 09:34:27 UTC 2026 - Jan Engelhardt <[email protected]>
+
+- Update to release 1.14.2
+  * Fix buffer overflows/overreads in `bssgp_rx_paging`,
+    `parse_process_uss_req`, `osmo_dec_gcr`, `osmo_pbit2ubit`, in
+    the CBSP WRITE-REPLACE decoder, and in TLV tag logging.
+  * iuup: Cure stack buffer-overflow rx IuUP with payload
+    larger than 1024 bytes.
+  * gsm: Reject BSSMAP Encryption Information IE with no selected
+    algo or key length != 8.
+
+-------------------------------------------------------------------

Old:
----
  libosmocore-1.14.1.tar.bz2

New:
----
  libosmocore-1.14.2.tar.bz2

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ libosmocore.spec ++++++
--- /var/tmp/diff_new_pack.56NBT8/_old  2026-08-21 17:02:52.381348648 +0200
+++ /var/tmp/diff_new_pack.56NBT8/_new  2026-08-21 17:02:52.386348825 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           libosmocore
-Version:        1.14.1
+Version:        1.14.2
 Release:        0
 Summary:        The Open Source Mobile Communications Core Library
 License:        AGPL-3.0-or-later AND GPL-2.0-only AND GPL-2.0-or-later AND 
LGPL-2.1-or-later

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.56NBT8/_old  2026-08-21 17:02:52.442350808 +0200
+++ /var/tmp/diff_new_pack.56NBT8/_new  2026-08-21 17:02:52.446350949 +0200
@@ -1,5 +1,5 @@
-mtime: 1784732036
-commit: 5f4f8cdd2199c1f7c8efd44e4574b21fbe235325a7e4bc37acc2868a728bdc05
+mtime: 1787305369
+commit: 28dc02f3dfadbe8c939a55c91daf2ef957b21769addad370fe4538c1becac3c3
 url: https://src.opensuse.org/jengelh/libosmocore
 revision: master
 

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-08-21 11:42:49.000000000 +0200
@@ -0,0 +1 @@
+.osc

++++++ libosmocore-1.14.1.tar.bz2 -> libosmocore-1.14.2.tar.bz2 ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/.tarball-version 
new/libosmocore-1.14.2/.tarball-version
--- old/libosmocore-1.14.1/.tarball-version     2026-07-22 12:35:27.000000000 
+0200
+++ new/libosmocore-1.14.2/.tarball-version     2026-08-21 07:21:04.000000000 
+0200
@@ -1 +1 @@
-1.14.1
+1.14.2
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/.version 
new/libosmocore-1.14.2/.version
--- old/libosmocore-1.14.1/.version     2026-07-22 12:35:23.000000000 +0200
+++ new/libosmocore-1.14.2/.version     2026-08-21 07:21:00.000000000 +0200
@@ -1 +1 @@
-1.14.1
+1.14.2
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/configure 
new/libosmocore-1.14.2/configure
--- old/libosmocore-1.14.1/configure    2026-07-22 12:35:12.000000000 +0200
+++ new/libosmocore-1.14.2/configure    2026-08-21 07:20:48.000000000 +0200
@@ -1,6 +1,6 @@
 #! /bin/sh
 # Guess values for system-dependent variables and create Makefiles.
-# Generated by GNU Autoconf 2.71 for libosmocore 1.14.1.
+# Generated by GNU Autoconf 2.71 for libosmocore 1.14.2.
 #
 # Report bugs to <[email protected]>.
 #
@@ -621,8 +621,8 @@
 # Identity of this package.
 PACKAGE_NAME='libosmocore'
 PACKAGE_TARNAME='libosmocore'
-PACKAGE_VERSION='1.14.1'
-PACKAGE_STRING='libosmocore 1.14.1'
+PACKAGE_VERSION='1.14.2'
+PACKAGE_STRING='libosmocore 1.14.2'
 PACKAGE_BUGREPORT='[email protected]'
 PACKAGE_URL=''
 
@@ -1548,7 +1548,7 @@
   # Omit some internal or obsolete options to make the list less imposing.
   # This message is too long to be a string in the A/UX 3.1 sh.
   cat <<_ACEOF
-\`configure' configures libosmocore 1.14.1 to adapt to many kinds of systems.
+\`configure' configures libosmocore 1.14.2 to adapt to many kinds of systems.
 
 Usage: $0 [OPTION]... [VAR=VALUE]...
 
@@ -1619,7 +1619,7 @@
 
 if test -n "$ac_init_help"; then
   case $ac_init_help in
-     short | recursive ) echo "Configuration of libosmocore 1.14.1:";;
+     short | recursive ) echo "Configuration of libosmocore 1.14.2:";;
    esac
   cat <<\_ACEOF
 
@@ -1819,7 +1819,7 @@
 test -n "$ac_init_help" && exit $ac_status
 if $ac_init_version; then
   cat <<\_ACEOF
-libosmocore configure 1.14.1
+libosmocore configure 1.14.2
 generated by GNU Autoconf 2.71
 
 Copyright (C) 2021 Free Software Foundation, Inc.
@@ -2287,7 +2287,7 @@
 This file contains any messages produced by compilers while
 running configure, to aid debugging if configure makes a mistake.
 
-It was created by libosmocore $as_me 1.14.1, which was
+It was created by libosmocore $as_me 1.14.2, which was
 generated by GNU Autoconf 2.71.  Invocation command line was
 
   $ $0$ac_configure_args_raw
@@ -3559,7 +3559,7 @@
 
 # Define the identity of the package.
  PACKAGE='libosmocore'
- VERSION='1.14.1'
+ VERSION='1.14.2'
 
 
 printf "%s\n" "#define PACKAGE \"$PACKAGE\"" >>confdefs.h
@@ -19078,7 +19078,7 @@
 # report actual input values of CONFIG_FILES etc. instead of their
 # values after options handling.
 ac_log="
-This file was extended by libosmocore $as_me 1.14.1, which was
+This file was extended by libosmocore $as_me 1.14.2, which was
 generated by GNU Autoconf 2.71.  Invocation command line was
 
   CONFIG_FILES    = $CONFIG_FILES
@@ -19146,7 +19146,7 @@
 cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
 ac_cs_config='$ac_cs_config_escaped'
 ac_cs_version="\\
-libosmocore config.status 1.14.1
+libosmocore config.status 1.14.2
 configured by $0, generated by GNU Autoconf 2.71,
   with options \\"\$ac_cs_config\\"
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/debian/changelog 
new/libosmocore-1.14.2/debian/changelog
--- old/libosmocore-1.14.1/debian/changelog     2026-07-22 12:35:06.000000000 
+0200
+++ new/libosmocore-1.14.2/debian/changelog     2026-08-21 07:20:41.000000000 
+0200
@@ -1,3 +1,35 @@
+libosmocore (1.14.2) unstable; urgency=medium
+
+  [ Pau Espin Pedrol ]
+  * tests/osmo_io: Remove unused variable
+  * iuup: Improve validation of header size
+  * iuup: Avoid stack buffer-overflow rx IuUP with payload >1024 bytes
+  * bits: Fix osmo_pbit2ubit() reading extra input byte on num_bits%8==0
+  * iuup: Fix formatting of log line printing payload checksum error
+  * iuup: Validate msgb input length in rx Initialization path
+  * iuup: test receival of IuUP Data with way too big payload
+  * gsm: Reject BSSMAP Encryption Information IE with no selected algo
+  * gsm: Reject BSSMAP Encryption Information IE with key length != 8
+  * gsm: Introduce gsm_septet_pack2() and deprecate gsm_septet_pack()
+  * tests/sms: Validate gsm_septet_pack2() succeeds
+
+  [ Vadim Yanitskiy ]
+  * gb: fix buffer overflow in bssgp_rx_paging()
+  * gsm0480: fix out-of-bounds read in parse_process_uss_req()
+  * gsm29205: fix out-of-bounds read in osmo_dec_gcr()
+  * gsm/ipa: fix out-of-bounds read in TLV tag logging
+  * gsm/ipa: reject t_len == 0 in ID_GET/ID_RESP TLV parsers
+  * gsm/ipa: fix t_len truncation in ipa_ccm_id_resp_parse()
+  * gsm0480: fix out-of-bounds reads in parse_ss_{invoke,return_result}()
+
+  [ Andreas Eversberg ]
+  * Add missing length check in gsm48_decode_callerid()
+
+  [ Adam Bedard ]
+  * gsm/cbsp: stack OOB read in the CBSP WRITE-REPLACE decoder
+
+ -- Pau Espin Pedrol <[email protected]>  Thu, 20 Aug 2026 10:02:21 +0200
+
 libosmocore (1.14.1) unstable; urgency=medium
 
   [ Vadim Yanitskiy ]
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/include/osmocom/core/version.h 
new/libosmocore-1.14.2/include/osmocom/core/version.h
--- old/libosmocore-1.14.1/include/osmocom/core/version.h       2026-07-22 
12:35:23.000000000 +0200
+++ new/libosmocore-1.14.2/include/osmocom/core/version.h       2026-08-21 
07:21:01.000000000 +0200
@@ -1,11 +1,11 @@
 #pragma once
 
-#define LIBOSMOCORE_VERSION 1.14.1
-#define LIBOSMOCORE_VERSION_STR "1.14.1"
+#define LIBOSMOCORE_VERSION 1.14.2
+#define LIBOSMOCORE_VERSION_STR "1.14.2"
 
 #define LIBOSMOCORE_VERSION_MAJOR 1
 #define LIBOSMOCORE_VERSION_MINOR 14
-#define LIBOSMOCORE_VERSION_PATCH 1
+#define LIBOSMOCORE_VERSION_PATCH 2
 
 #define LIBOSMOCORE_VERSION_GREATER_EQUAL(major, minor, patch) \
        (LIBOSMOCORE_VERSION_MAJOR > (major) || \
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/include/osmocom/gsm/gsm_utils.h 
new/libosmocore-1.14.2/include/osmocom/gsm/gsm_utils.h
--- old/libosmocore-1.14.1/include/osmocom/gsm/gsm_utils.h      2026-07-22 
12:35:06.000000000 +0200
+++ new/libosmocore-1.14.2/include/osmocom/gsm/gsm_utils.h      2026-08-21 
07:20:41.000000000 +0200
@@ -109,8 +109,10 @@
 /* the four functions below are helper functions and here for the unit test */
 int gsm_septets2octets(uint8_t *result, const uint8_t *rdata, uint8_t 
septet_len, uint8_t padding)
        OSMO_DEPRECATED("This function is unable to handle more than 255 
septets, "
-                       "use gsm_septet_pack() instead.");
-int gsm_septet_pack(uint8_t *result, const uint8_t *rdata, size_t septet_len, 
uint8_t padding);
+                       "use gsm_septet_pack2() instead.");
+int gsm_septet_pack(uint8_t *result, const uint8_t *rdata, size_t septet_len, 
uint8_t padding)
+       OSMO_DEPRECATED("This function is not write-safe, use 
gsm_septet_pack2() instead.");
+int gsm_septet_pack2(uint8_t *result, size_t result_size, const uint8_t 
*rdata, size_t septet_len, uint8_t padding);
 int gsm_septet_encode(uint8_t *result, const char *data);
 uint8_t gsm_get_octet_len(const uint8_t sept_len);
 int gsm_7bit_decode_n_hdr(char *decoded, size_t n, const uint8_t *user_data, 
uint8_t length, uint8_t ud_hdr_ind);
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/libosmocore-1.14.1/include/osmocom/gsm/protocol/gsm_25_415.h 
new/libosmocore-1.14.2/include/osmocom/gsm/protocol/gsm_25_415.h
--- old/libosmocore-1.14.1/include/osmocom/gsm/protocol/gsm_25_415.h    
2026-07-22 12:35:06.000000000 +0200
+++ new/libosmocore-1.14.2/include/osmocom/gsm/protocol/gsm_25_415.h    
2026-08-21 07:20:41.000000000 +0200
@@ -158,9 +158,9 @@
 
 /* 3GPP TS 25.415 Section 6.6.2 + 6.6.3.1 */
 enum iuup_pdu_type {
-       IUUP_PDU_T_DATA_CRC     = 0,
-       IUUP_PDU_T_DATA_NOCRC   = 1,
-       IUUP_PDU_T_CONTROL      = 14,
+       IUUP_PDU_T_DATA_CRC     = 0, /* PDU Type 0 */
+       IUUP_PDU_T_DATA_NOCRC   = 1, /* PDU Type 1 */
+       IUUP_PDU_T_CONTROL      = 14, /* PDU Type 14 */
 };
 
 /* 3GPP TS 25.415 Section 6.6.3.2 */
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/src/core/Makefile.am 
new/libosmocore-1.14.2/src/core/Makefile.am
--- old/libosmocore-1.14.1/src/core/Makefile.am 2026-07-22 12:35:06.000000000 
+0200
+++ new/libosmocore-1.14.2/src/core/Makefile.am 2026-08-21 07:20:41.000000000 
+0200
@@ -1,7 +1,7 @@
 # This is _NOT_ the library release version, it's an API version.
 # Please read chapter "Library interface versions" of the libtool documentation
 # before making any modifications: 
https://www.gnu.org/software/libtool/manual/html_node/Versioning.html
-LIBVERSION=26:1:4
+LIBVERSION=26:2:4
 
 AM_CPPFLAGS = -I$(top_srcdir)/include -I$(top_builddir)/include 
-I$(top_builddir)
 AM_CFLAGS = -Wall $(TALLOC_CFLAGS) $(PTHREAD_CFLAGS) $(LIBSCTP_CFLAGS) 
$(LIBMNL_CFLAGS) $(URING_CFLAGS)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/src/core/Makefile.in 
new/libosmocore-1.14.2/src/core/Makefile.in
--- old/libosmocore-1.14.1/src/core/Makefile.in 2026-07-22 12:35:13.000000000 
+0200
+++ new/libosmocore-1.14.2/src/core/Makefile.in 2026-08-21 07:20:49.000000000 
+0200
@@ -513,7 +513,7 @@
 # This is _NOT_ the library release version, it's an API version.
 # Please read chapter "Library interface versions" of the libtool documentation
 # before making any modifications: 
https://www.gnu.org/software/libtool/manual/html_node/Versioning.html
-LIBVERSION = 26:1:4
+LIBVERSION = 26:2:4
 AM_CPPFLAGS = -I$(top_srcdir)/include -I$(top_builddir)/include \
        -I$(top_builddir) $(am__append_1)
 AM_CFLAGS = -Wall $(TALLOC_CFLAGS) $(PTHREAD_CFLAGS) $(LIBSCTP_CFLAGS) 
$(LIBMNL_CFLAGS) $(URING_CFLAGS)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/src/core/bits.c 
new/libosmocore-1.14.2/src/core/bits.c
--- old/libosmocore-1.14.1/src/core/bits.c      2026-07-22 12:35:06.000000000 
+0200
+++ new/libosmocore-1.14.2/src/core/bits.c      2026-08-21 07:20:41.000000000 
+0200
@@ -139,6 +139,8 @@
  *  \param[in] in input buffer of packed bits
  *  \param[in] num_bits number of bits
  *  \return number of bytes used in \ref out
+ *
+ *  Note: size of out array is expected to be ">= num_bits" bytes.
  */
 int osmo_pbit2ubit(ubit_t *out, const pbit_t *in, unsigned int num_bits)
 {
@@ -146,7 +148,7 @@
        ubit_t *cur = out;
        ubit_t *limit = out + num_bits;
 
-       for (i = 0; i < (num_bits/8)+1; i++) {
+       for (i = 0; i < ((num_bits + 7) / 8); i++) {
                pbit_t byte = in[i];
                *cur++ = (byte >> 7) & 1;
                if (cur >= limit)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/src/gb/Makefile.am 
new/libosmocore-1.14.2/src/gb/Makefile.am
--- old/libosmocore-1.14.1/src/gb/Makefile.am   2026-07-22 12:35:06.000000000 
+0200
+++ new/libosmocore-1.14.2/src/gb/Makefile.am   2026-08-21 07:20:41.000000000 
+0200
@@ -1,7 +1,7 @@
 # This is _NOT_ the library release version, it's an API version.
 # Please read chapter "Library interface versions" of the libtool documentation
 # before making any modifications: 
https://www.gnu.org/software/libtool/manual/html_node/Versioning.html
-LIBVERSION=17:2:3
+LIBVERSION=17:3:3
 
 AM_CPPFLAGS = -I$(top_srcdir)/include -I$(top_builddir)/include 
-I$(top_builddir)
 AM_CFLAGS = -Wall -fno-strict-aliasing \
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/src/gb/Makefile.in 
new/libosmocore-1.14.2/src/gb/Makefile.in
--- old/libosmocore-1.14.1/src/gb/Makefile.in   2026-07-22 12:35:13.000000000 
+0200
+++ new/libosmocore-1.14.2/src/gb/Makefile.in   2026-08-21 07:20:49.000000000 
+0200
@@ -470,7 +470,7 @@
 # This is _NOT_ the library release version, it's an API version.
 # Please read chapter "Library interface versions" of the libtool documentation
 # before making any modifications: 
https://www.gnu.org/software/libtool/manual/html_node/Versioning.html
-LIBVERSION = 17:2:3
+LIBVERSION = 17:3:3
 AM_CPPFLAGS = -I$(top_srcdir)/include -I$(top_builddir)/include 
-I$(top_builddir)
 AM_CFLAGS = -Wall -fno-strict-aliasing \
            $(TALLOC_CFLAGS) \
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/src/gb/gprs_bssgp_bss.c 
new/libosmocore-1.14.2/src/gb/gprs_bssgp_bss.c
--- old/libosmocore-1.14.1/src/gb/gprs_bssgp_bss.c      2026-07-22 
12:35:06.000000000 +0200
+++ new/libosmocore-1.14.2/src/gb/gprs_bssgp_bss.c      2026-08-21 
07:20:41.000000000 +0200
@@ -479,11 +479,8 @@
        struct bssgp_normal_hdr *bgph =
                        (struct bssgp_normal_hdr *) msgb_bssgph(msg);
        struct tlv_parsed tp;
-       uint8_t ra[6];
        int rc, data_len;
 
-       memset(ra, 0, sizeof(ra));
-
        data_len = msgb_bssgp_len(msg) - sizeof(*bgph);
        rc = bssgp_tlv_parse(&tp, bgph->data, data_len);
        if (rc < 0)
@@ -519,14 +516,10 @@
                pinfo->scope = BSSGP_PAGING_BSS_AREA;
        } else if (TLVP_PRES_LEN(&tp, BSSGP_IE_LOCATION_AREA, 5)) {
                pinfo->scope = BSSGP_PAGING_LOCATION_AREA;
-               memcpy(ra, TLVP_VAL(&tp, BSSGP_IE_LOCATION_AREA),
-                       TLVP_LEN(&tp, BSSGP_IE_LOCATION_AREA));
-               gsm48_parse_ra(&pinfo->raid, ra);
+               gsm48_parse_ra(&pinfo->raid, TLVP_VAL(&tp, 
BSSGP_IE_LOCATION_AREA));
        } else if (TLVP_PRES_LEN(&tp, BSSGP_IE_ROUTEING_AREA, 6)) {
                pinfo->scope = BSSGP_PAGING_ROUTEING_AREA;
-               memcpy(ra, TLVP_VAL(&tp, BSSGP_IE_ROUTEING_AREA),
-                       TLVP_LEN(&tp, BSSGP_IE_ROUTEING_AREA));
-               gsm48_parse_ra(&pinfo->raid, ra);
+               gsm48_parse_ra(&pinfo->raid, TLVP_VAL(&tp, 
BSSGP_IE_ROUTEING_AREA));
        } else if (TLVP_PRES_LEN(&tp, BSSGP_IE_BVCI, 2)) {
                pinfo->scope = BSSGP_PAGING_BVCI;
                pinfo->bvci = tlvp_val16be(&tp, BSSGP_IE_BVCI);
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/Makefile.am 
new/libosmocore-1.14.2/src/gsm/Makefile.am
--- old/libosmocore-1.14.1/src/gsm/Makefile.am  2026-07-22 12:35:06.000000000 
+0200
+++ new/libosmocore-1.14.2/src/gsm/Makefile.am  2026-08-21 07:20:41.000000000 
+0200
@@ -1,7 +1,7 @@
 # This is _NOT_ the library release version, it's an API version.
 # Please read chapter "Library interface versions" of the libtool documentation
 # before making any modifications: 
https://www.gnu.org/software/libtool/manual/html_node/Versioning.html
-LIBVERSION=24:1:4
+LIBVERSION=25:0:5
 
 AM_CPPFLAGS = -I$(top_srcdir)/include -I$(top_builddir)/include
 AM_CFLAGS = -Wall $(TALLOC_CFLAGS)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/Makefile.in 
new/libosmocore-1.14.2/src/gsm/Makefile.in
--- old/libosmocore-1.14.1/src/gsm/Makefile.in  2026-07-22 12:35:13.000000000 
+0200
+++ new/libosmocore-1.14.2/src/gsm/Makefile.in  2026-08-21 07:20:49.000000000 
+0200
@@ -511,7 +511,7 @@
 # This is _NOT_ the library release version, it's an API version.
 # Please read chapter "Library interface versions" of the libtool documentation
 # before making any modifications: 
https://www.gnu.org/software/libtool/manual/html_node/Versioning.html
-LIBVERSION = 24:1:4
+LIBVERSION = 25:0:5
 AM_CPPFLAGS = -I$(top_srcdir)/include -I$(top_builddir)/include \
        $(am__append_1)
 AM_CFLAGS = -Wall $(TALLOC_CFLAGS) $(am__append_3)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/cbsp.c 
new/libosmocore-1.14.2/src/gsm/cbsp.c
--- old/libosmocore-1.14.1/src/gsm/cbsp.c       2026-07-22 12:35:06.000000000 
+0200
+++ new/libosmocore-1.14.2/src/gsm/cbsp.c       2026-08-21 07:20:41.000000000 
+0200
@@ -633,6 +633,7 @@
 /***********************************************************************
  * Message Decoding
  ***********************************************************************/
+#define MAX_NUM_CBS_PAGES 16 /* max. number of pages in a given CBS message */
 
 /* 8.1.3.1 WRITE REPLACE */
 static int cbsp_dec_write_repl(struct osmo_cbsp_write_replace *out, const 
struct tlv_parsed *tp,
@@ -684,8 +685,10 @@
                out->u.cbs.num_bcast_req = tlvp_val16be(tp, 
CBSP_IEI_NUM_BCAST_REQ);
                out->u.cbs.dcs = *TLVP_VAL(tp, CBSP_IEI_DCS);
                num_of_pages = *TLVP_VAL(tp, CBSP_IEI_NUM_OF_PAGES);
-               if (num_of_pages < 1)
+               if (num_of_pages < 1 || num_of_pages > MAX_NUM_CBS_PAGES) {
+                       osmo_cbsp_errstr = "invalid number of pages";
                        return -EINVAL;
+               }
                /* parse pages */
                for (i = 0; i < num_of_pages; i++) {
                        const uint8_t *ie = TLVP_VAL(&tp[i], 
CBSP_IEI_MSG_CONTENT);
@@ -1264,7 +1267,7 @@
        OSMO_ASSERT(in->l1h != NULL && in->l2h != NULL);
        struct osmo_cbsp_decoded *out = talloc_zero(ctx, struct 
osmo_cbsp_decoded);
        const struct cbsp_header *h = msgb_l1(in);
-       struct tlv_parsed tp[16]; /* max. number of pages in a given CBS 
message */
+       struct tlv_parsed tp[MAX_NUM_CBS_PAGES];
        unsigned int len;
        int rc;
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/gsm0480.c 
new/libosmocore-1.14.2/src/gsm/gsm0480.c
--- old/libosmocore-1.14.1/src/gsm/gsm0480.c    2026-07-22 12:35:06.000000000 
+0200
+++ new/libosmocore-1.14.2/src/gsm/gsm0480.c    2026-08-21 07:20:41.000000000 
+0200
@@ -548,17 +548,24 @@
        offset = invoke_data[1] + 2;
        req->invoke_id = invoke_data[2];
 
-       /* look ahead once */
-       if (offset + 1 > length)
+       /* look ahead once: need invoke_data[offset] and, if it turns out to be
+        * the optional Linked ID tag, invoke_data[offset+1] as well */
+       if (offset + 2 > length)
                return 0;
 
        /* optional part */
-       if (invoke_data[offset] == GSM0480_COMPIDTAG_LINKED_ID)
+       if (invoke_data[offset] == GSM0480_COMPIDTAG_LINKED_ID) {
                offset += invoke_data[offset+1] + 2;  /* skip over it */
 
+               /* offset moved by an attacker-controlled amount: re-validate */
+               if (offset >= length)
+                       return 0;
+       }
+
        /* mandatory part */
        if (invoke_data[offset] == GSM0480_OPERATION_CODE) {
-               if (offset + 2 > length)
+               /* need invoke_data[offset+2] below, and length - offset - 3 
must not underflow */
+               if (offset + 3 > length)
                        return 0;
                uint8_t operation_code = invoke_data[offset+2];
                req->opcode = operation_code;
@@ -624,10 +631,12 @@
        if (rr_data[offset] != GSM_0480_SEQUENCE_TAG)
                return 0;
 
-       if (offset + 2 > length)
+       offset += 2;
+
+       /* need rr_data[offset+2] below, and length - offset - 3 must not 
underflow */
+       if (offset + 3 > length)
                return 0;
 
-       offset += 2;
        operation_code = rr_data[offset + 2];
        req->opcode = operation_code;
 
@@ -704,6 +713,8 @@
        dcs = uss_req_data[4];
        /* Get the amount of bytes */
        num_chars = uss_req_data[6];
+       if (num_chars > length - 7)
+               return 0;
 
        /* Drop messages with incorrect length */
        if (num_chars > GSM0480_USSD_OCTET_STRING_LEN) {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/gsm0808_utils.c 
new/libosmocore-1.14.2/src/gsm/gsm0808_utils.c
--- old/libosmocore-1.14.1/src/gsm/gsm0808_utils.c      2026-07-22 
12:35:06.000000000 +0200
+++ new/libosmocore-1.14.2/src/gsm/gsm0808_utils.c      2026-08-21 
07:20:41.000000000 +0200
@@ -820,7 +820,7 @@
        return *tlv_len + 2;
 }
 
-/*! Decode TS 08.08 Encryption Information IE
+/*! Decode 3GPP TS 48.008 3.2.2.10 Encryption Information IE
  *  \param[out] ei Caller-provided memory to store encryption information
  *  \param[in] elem IE value to be decoded
  *  \param[in] len Length of \a elem in bytes
@@ -831,7 +831,6 @@
        uint8_t perm_algo;
        unsigned int i;
        unsigned int perm_algo_len = 0;
-       const uint8_t *old_elem = elem;
 
        if (!elem)
                return -EINVAL;
@@ -843,6 +842,10 @@
        perm_algo = *elem;
        elem++;
 
+       /* "A permitted algorithms octet containing all bits encoded as 0 shall 
not be used." */
+       if (perm_algo == 0x00)
+               return -EINVAL;
+
        for (i = 0; i < ENCRY_INFO_PERM_ALGO_MAXLEN; i++) {
                if (perm_algo & (1 << i)) {
                        ei->perm_algo[perm_algo_len] = i + 1;
@@ -850,14 +853,18 @@
                }
        }
        ei->perm_algo_len = perm_algo_len;
-
-       /* FIXME: 48.008 3.2.2.10 Encryption Information says:
-        * "When present, the key shall be 8 octets long." */
        ei->key_len = len - 1;
-       memcpy(ei->key, elem, ei->key_len);
-       elem+=ei->key_len;
 
-       return (int)(elem - old_elem);
+       /* No key present, done */
+       if (ei->key_len == 0)
+               return len;
+
+       /* "When present, the key shall be 8 octets long." */
+       if (ei->key_len != 8)
+               return -EINVAL;
+       OSMO_ASSERT(sizeof(ei->key) >= ei->key_len);
+       memcpy(ei->key, elem, ei->key_len);
+       return len;
 }
 
 /*! Encode TS 48.008 Kc128 IE.
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/gsm29205.c 
new/libosmocore-1.14.2/src/gsm/gsm29205.c
--- old/libosmocore-1.14.1/src/gsm/gsm29205.c   2026-07-22 12:35:06.000000000 
+0200
+++ new/libosmocore-1.14.2/src/gsm/gsm29205.c   2026-08-21 07:20:41.000000000 
+0200
@@ -73,6 +73,8 @@
        gcr->net_len = elem[0];
        if (gcr->net_len < 3 || gcr->net_len > 5)
                return -EINVAL;
+       if (len < 10 + gcr->net_len)
+               return -EBADMSG;
 
        memcpy(gcr->net, elem + parsed, gcr->net_len);
        /* +1 for ignored Node ID length field */
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/gsm48_ie.c 
new/libosmocore-1.14.2/src/gsm/gsm48_ie.c
--- old/libosmocore-1.14.1/src/gsm/gsm48_ie.c   2026-07-22 12:35:06.000000000 
+0200
+++ new/libosmocore-1.14.2/src/gsm/gsm48_ie.c   2026-08-21 07:20:41.000000000 
+0200
@@ -491,6 +491,8 @@
 
        /* octet 3a */
        if (!(lv[1] & 0x80)) {
+               if (in_len < 2)
+                       return -EINVAL;
                callerid->screen = lv[2] & 0x03;
                callerid->present = (lv[2] & 0x60) >> 5;
                i = 2;
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/gsm_utils.c 
new/libosmocore-1.14.2/src/gsm/gsm_utils.c
--- old/libosmocore-1.14.1/src/gsm/gsm_utils.c  2026-07-22 12:35:06.000000000 
+0200
+++ new/libosmocore-1.14.2/src/gsm/gsm_utils.c  2026-08-21 07:20:41.000000000 
+0200
@@ -90,6 +90,7 @@
 #include <errno.h>
 #include <ctype.h>
 #include <inttypes.h>
+#include <limits.h>
 #include <time.h>
 #include <unistd.h>
 
@@ -317,11 +318,12 @@
 
 /*! GSM Default Alphabet 7bit to octet packing
  *  \param[out] result Caller-provided output buffer
+ *  \param[in] result_size Caller-provided output buffer size
  *  \param[in] rdata Input data septets
  *  \param[in] septet_len Length of \a rdata
  *  \param[in] padding padding bits at start
- *  \returns number of bytes used in \a result */
-int gsm_septet_pack(uint8_t *result, const uint8_t *rdata, size_t septet_len, 
uint8_t padding)
+ *  \returns number of bytes used in \a result, negative on error */
+int gsm_septet_pack2(uint8_t *result, size_t result_size, const uint8_t 
*rdata, size_t septet_len, uint8_t padding)
 {
        int i = 0, z = 0;
        uint8_t cb, nb;
@@ -358,6 +360,10 @@
                        cb = cb | nb;
                }
 
+               if (z == result_size) {
+                       free(data);
+                       return -ENOBUFS;
+               }
                result[z++] = cb;
                shift++;
        }
@@ -367,10 +373,21 @@
        return z;
 }
 
+/*! GSM Default Alphabet 7bit to octet packing
+ *  \param[out] result Caller-provided output buffer
+ *  \param[in] rdata Input data septets
+ *  \param[in] septet_len Length of \a rdata
+ *  \param[in] padding padding bits at start
+ *  \returns number of bytes used in \a result, negative on error */
+int gsm_septet_pack(uint8_t *result, const uint8_t *rdata, size_t septet_len, 
uint8_t padding)
+{
+       return gsm_septet_pack2(result, INT_MAX, rdata, septet_len, padding);
+}
+
 /*! Backwards compatibility wrapper for gsm_septets_pack(), deprecated. */
 int gsm_septets2octets(uint8_t *result, const uint8_t *rdata, uint8_t 
septet_len, uint8_t padding)
 {
-       return gsm_septet_pack(result, rdata, septet_len, padding);
+       return gsm_septet_pack2(result, INT_MAX, rdata, septet_len, padding);
 }
 
 /*! GSM 7-bit alphabet TS 03.38 6.2.1 Character packing
@@ -397,7 +414,7 @@
                y = max_septets;
        }
 
-       o = gsm_septet_pack(result, rdata, y, 0);
+       o = gsm_septet_pack2(result, n, rdata, y, 0);
 
        if (octets)
                *octets = o;
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/ipa.c 
new/libosmocore-1.14.2/src/gsm/ipa.c
--- old/libosmocore-1.14.1/src/gsm/ipa.c        2026-07-22 12:35:06.000000000 
+0200
+++ new/libosmocore-1.14.2/src/gsm/ipa.c        2026-08-21 07:20:41.000000000 
+0200
@@ -139,7 +139,7 @@
                        return -EINVAL;
                }
 
-               LOGPC(DLMI, LOGL_DEBUG, "%s='%s' ", ipa_ccm_idtag_name(t_tag), 
cur);
+               LOGPC(DLMI, LOGL_DEBUG, "%s='%.*s' ", 
ipa_ccm_idtag_name(t_tag), t_len - len_offset, cur);
 
                dec->lv[t_tag].len = t_len - len_offset;
                dec->lv[t_tag].val = cur;
@@ -174,13 +174,19 @@
                t_len = *cur++;
                t_tag = *cur++;
 
+               if (t_len < 1) {
+                       LOGPC(DLMI, LOGL_DEBUG, "\n");
+                       LOGP(DLMI, LOGL_ERROR, "The tag length is too short: %d 
< 1\n", t_len);
+                       return -EINVAL;
+               }
+
                if (t_len > len + 1) {
                        LOGPC(DLMI, LOGL_DEBUG, "\n");
                        LOGP(DLMI, LOGL_ERROR, "The tag does not fit: %d > 
%d\n", t_len, len + 1);
                        return -EINVAL;
                }
 
-               LOGPC(DLMI, LOGL_DEBUG, "%s='%s' ", ipa_ccm_idtag_name(t_tag), 
cur);
+               LOGPC(DLMI, LOGL_DEBUG, "%s='%.*s' ", 
ipa_ccm_idtag_name(t_tag), t_len - 1, cur);
 
                dec->lv[t_tag].len = t_len-1;
                dec->lv[t_tag].val = cur;
@@ -203,7 +209,7 @@
  *  \returns 0 on success; negative on error */
 int ipa_ccm_id_resp_parse(struct tlv_parsed *dec, const uint8_t *buf, unsigned 
int len)
 {
-       uint8_t t_len;
+       uint16_t t_len;
        uint8_t t_tag;
        const uint8_t *cur = buf;
 
@@ -216,13 +222,19 @@
                cur += 2;
                t_tag = *cur++;
 
+               if (t_len < 1) {
+                       LOGPC(DLMI, LOGL_DEBUG, "\n");
+                       LOGP(DLMI, LOGL_ERROR, "The tag length is too short: %d 
< 1\n", t_len);
+                       return -EINVAL;
+               }
+
                if (t_len > len + 1) {
                        LOGPC(DLMI, LOGL_DEBUG, "\n");
                        LOGP(DLMI, LOGL_ERROR, "The tag does not fit: %d > 
%d\n", t_len, len + 1);
                        return -EINVAL;
                }
 
-               DEBUGPC(DLMI, "%s='%s' ", ipa_ccm_idtag_name(t_tag), cur);
+               DEBUGPC(DLMI, "%s='%.*s' ", ipa_ccm_idtag_name(t_tag), t_len - 
1, cur);
 
                dec->lv[t_tag].len = t_len-1;
                dec->lv[t_tag].val = cur;
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/iuup.c 
new/libosmocore-1.14.2/src/gsm/iuup.c
--- old/libosmocore-1.14.1/src/gsm/iuup.c       2026-07-22 12:35:06.000000000 
+0200
+++ new/libosmocore-1.14.2/src/gsm/iuup.c       2026-08-21 07:20:41.000000000 
+0200
@@ -70,9 +70,12 @@
 
 int osmo_iuup_compute_payload_crc(const uint8_t *iuup_pdu, unsigned int 
pdu_len)
 {
-       ubit_t buf[1024*8];
+       /* Assume no IuUP payloads bigger than a regular ethernet frame: */
+       const unsigned int max_supported_iuup_payload_len_bytes = 1500;
+       ubit_t buf[max_supported_iuup_payload_len_bytes * 8];
        uint8_t pdu_type;
-       int offset, payload_len_bytes;
+       int offset;
+       unsigned int payload_len_bytes;
 
        if (pdu_len < 1)
                return -1;
@@ -91,6 +94,11 @@
                return -1;
 
        payload_len_bytes = pdu_len - offset;
+
+       /* Guard against osmo_pbit2ubit writing past buf: */
+       if (payload_len_bytes > max_supported_iuup_payload_len_bytes)
+               return -1;
+
        osmo_pbit2ubit(buf, iuup_pdu+offset, payload_len_bytes*8);
        return osmo_crc16gen_compute_bits(&iuup_data_crc_code, buf, 
payload_len_bytes*8);
 }
@@ -531,7 +539,8 @@
 /* return: whether the last Init was Acked correctly and hence can transition 
to next state */
 static bool iuup_rx_initialization(struct osmo_iuup_instance *iui, struct 
osmo_iuup_tnl_prim *itp)
 {
-       struct iuup_pdutype14_hdr *hdr;
+       struct msgb *msg = itp->oph.msg;
+       struct iuup_pdutype14_hdr *hdr = (struct iuup_pdutype14_hdr 
*)msgb_l2(msg);
        struct iuup_ctrl_init_hdr *ihdr;
        struct iuup_ctrl_init_rfci_hdr *ihdr_rfci;
        struct iuup_ctrl_init_tail *itail;
@@ -543,9 +552,16 @@
        struct osmo_iuup_rnl_prim *irp;
        struct osmo_iuup_tnl_prim *resp;
 
-       /* TODO: whenever we check message boundaries, length, etc. and we 
fail, send NACK */
+       /* We expect at least the INIT header with at least 1 RFCI header: */
+       if (msgb_l2len(msg) < sizeof(struct iuup_pdutype14_hdr) +
+                             sizeof(struct iuup_ctrl_init_hdr) +
+                             sizeof(struct iuup_ctrl_init_rfci_hdr)) {
+               LOGPFSML(iui->fi, LOGL_NOTICE,
+                        "Initialization: Malformed packet, length %u too 
short\n", msgb_l2len(msg));
+               err_cause = IUUP_ERR_CAUSE_FRAME_TOO_SHORT;
+               goto send_nack;
+       }
 
-       hdr = (struct iuup_pdutype14_hdr *)msgb_l2(itp->oph.msg);
        ihdr = (struct iuup_ctrl_init_hdr *)hdr->payload;
        if (ihdr->num_subflows_per_rfci == 0) {
                LOGPFSML(iui->fi, LOGL_NOTICE, "Initialization: Unexpected 
num_subflows=0 received\n");
@@ -554,16 +570,33 @@
        }
        ihdr_rfci = (struct iuup_ctrl_init_rfci_hdr *)ihdr->rfci_data;
 
+       /* Iterate over RFCIs and parse and store its subflow lengths: */
        do {
                struct osmo_iuup_rfci *rfci = &iui->config.rfci[num_rfci];
                uint8_t l_size_bytes = ihdr_rfci->li + 1;
+               struct iuup_ctrl_init_rfci_hdr *next_ihdr_rfci =
+                       (struct iuup_ctrl_init_rfci_hdr 
*)(&ihdr_rfci->subflow_length[0] +
+                                                          
(ihdr->num_subflows_per_rfci * l_size_bytes));
                is_last = ihdr_rfci->lri;
+
                if (num_rfci >= IUUP_MAX_RFCIS) {
                        LOGPFSML(iui->fi, LOGL_NOTICE, "Initialization: Too 
many RFCIs received (%u)\n",
-                                        num_rfci);
+                                num_rfci);
                        err_cause = IUUP_ERR_CAUSE_UNEXPECTED_RFCI;
                        goto send_nack;
                }
+
+               /* Check contents of current RFCI are available in msgb, and if 
not last RFCI,
+                * also check for availability of next ihdr_rfci, all in one 
go: */
+               if ((((uint8_t *)next_ihdr_rfci) + (is_last ? 0 : sizeof(struct 
iuup_ctrl_init_rfci_hdr))) >
+                   msg->tail) {
+                       LOGPFSML(iui->fi, LOGL_NOTICE,
+                               "Initialization: Malformed packet, length %u 
too short\n",
+                               msgb_l2len(msg));
+                       err_cause = IUUP_ERR_CAUSE_FRAME_TOO_SHORT;
+                       goto send_nack;
+               }
+
                rfci->used = 1;
                rfci->id = ihdr_rfci->rfci;
                if (l_size_bytes == 2) {
@@ -580,13 +613,21 @@
                        }
                }
                num_rfci++;
-               ihdr_rfci++;
-               ihdr_rfci = (struct iuup_ctrl_init_rfci_hdr *)(((uint8_t 
*)ihdr_rfci) + ihdr->num_subflows_per_rfci * l_size_bytes);
+               ihdr_rfci = next_ihdr_rfci;
        } while (!is_last);
 
        if (ihdr->ti) { /* Timing information present */
                uint8_t *buf = (uint8_t *)ihdr_rfci;
                uint8_t num_bytes = (num_rfci + 1) / 2;
+
+               if (buf + num_bytes > msg->tail) {
+                       LOGPFSML(iui->fi, LOGL_NOTICE,
+                                "Initialization: Malformed packet, length %u 
too short\n",
+                                msgb_l2len(msg));
+                       err_cause = IUUP_ERR_CAUSE_FRAME_TOO_SHORT;
+                       goto send_nack;
+               }
+
                iui->config.IPTIs_present = true;
                for (i = 0; i < num_bytes - 1; i++) {
                        iui->config.rfci[i*2].IPTI = *buf >> 4;
@@ -602,6 +643,15 @@
                iui->config.IPTIs_present = false;
                itail = (struct iuup_ctrl_init_tail *)ihdr_rfci;
        }
+
+       if (((uint8_t *)itail) + sizeof(*itail) > msg->tail) {
+               LOGPFSML(iui->fi, LOGL_NOTICE,
+                        "Initialization: Malformed packet, length %u too 
short\n",
+                        msgb_l2len(msg));
+               err_cause = IUUP_ERR_CAUSE_FRAME_TOO_SHORT;
+               goto send_nack;
+       }
+
        if (itail->data_pdu_type > 1) {
                LOGPFSML(iui->fi, LOGL_NOTICE, "Initialization: Unexpected Data 
PDU Type %u received\n", itail->data_pdu_type);
                err_cause = IUUP_ERR_CAUSE_UNEXPECTED_VALUE;
@@ -635,9 +685,10 @@
        resp = itp_ctrl_ack_alloc(iui, IUUP_PROC_INIT, hdr->frame_nr);
        iui->transport_prim_cb(&resp->oph, iui->transport_prim_priv);
        return ihdr->chain_ind == 0;
+
 send_nack:
        LOGPFSML(iui->fi, LOGL_NOTICE, "Tx Initialization NACK cause=%u 
orig_message=%s\n",
-                err_cause, osmo_hexdump((const unsigned char *) 
msgb_l2(itp->oph.msg), msgb_l2len(itp->oph.msg)));
+                err_cause, osmo_hexdump((const unsigned char *) msgb_l2(msg), 
msgb_l2len(msg)));
        resp = tnp_ctrl_nack_alloc(iui, IUUP_PROC_INIT, err_cause, 
hdr->frame_nr);
        iui->transport_prim_cb(&resp->oph, iui->transport_prim_priv);
        return false;
@@ -871,7 +922,7 @@
        struct iuup_pdutype0_hdr *t0h;
        struct iuup_pdutype14_hdr *t14h;
 
-       if (len < 3)
+       if (len < 3) /* common minimum length for all IuUP packet types */
                return -EINVAL;
 
        header_crc_computed = osmo_iuup_compute_header_crc(data, len);
@@ -881,22 +932,30 @@
                return -EIO;
        }
        switch (pdu_type) {
-       case IUUP_PDU_T_DATA_NOCRC:
-               if (len < 4)
+       case IUUP_PDU_T_DATA_CRC: /* PDU Type 0 */
+               if (len < sizeof(struct iuup_pdutype0_hdr))
                        return -EINVAL;
-               break;
-       case IUUP_PDU_T_DATA_CRC:
                t0h = (struct iuup_pdutype0_hdr *) data;
                payload_crc = ((uint16_t)t0h->payload_crc_hi << 8) | 
t0h->payload_crc_lo;
                payload_crc_computed = osmo_iuup_compute_payload_crc(data, len);
+               if (payload_crc_computed < 0)
+                       goto payload_crc_err;
                if (payload_crc != payload_crc_computed)
                        goto payload_crc_err;
                break;
-       case IUUP_PDU_T_CONTROL:
+       case IUUP_PDU_T_DATA_NOCRC: /* PDU Type 1 */
+               if (len < sizeof(struct iuup_pdutype1_hdr))
+                       return -EINVAL;
+               break;
+       case IUUP_PDU_T_CONTROL: /* PDU Type 14 */
+               if (len < sizeof(struct iuup_pdutype14_hdr))
+                       return -EINVAL;
                t14h = (struct iuup_pdutype14_hdr *) data;
                if (t14h->ack_nack == IUUP_AN_PROCEDURE) {
                        payload_crc = ((uint16_t)t14h->payload_crc_hi << 8) | 
t14h->payload_crc_lo;
                        payload_crc_computed = 
osmo_iuup_compute_payload_crc(data, len);
+                       if (payload_crc_computed < 0)
+                               goto payload_crc_err;
                        if (payload_crc != payload_crc_computed)
                                goto payload_crc_err;
                }
@@ -907,8 +966,13 @@
        return 0;
 
 payload_crc_err:
-       LOGP(DLIUUP, LOGL_NOTICE, "Payload Checksum error (pdu type %u): rx 
0x%02x vs exp 0x%02x\n",
-            pdu_type, payload_crc, payload_crc_computed);
+       if (payload_crc_computed < 0) {
+               LOGP(DLIUUP, LOGL_NOTICE, "Payload Checksum failed (pdu type 
%u): Packet too big? length %u\n",
+                    pdu_type, len);
+       } else {
+               LOGP(DLIUUP, LOGL_NOTICE, "Payload Checksum error (pdu type 
%u): rx 0x%04x vs exp 0x%04x\n",
+                    pdu_type, payload_crc, payload_crc_computed);
+       }
        return -EIO;
 }
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/libosmogsm.map 
new/libosmocore-1.14.2/src/gsm/libosmogsm.map
--- old/libosmocore-1.14.1/src/gsm/libosmogsm.map       2026-07-22 
12:35:06.000000000 +0200
+++ new/libosmocore-1.14.2/src/gsm/libosmogsm.map       2026-08-21 
07:20:41.000000000 +0200
@@ -566,6 +566,7 @@
 gsm_milenage;
 gsm_septet_encode;
 gsm_septet_pack;
+gsm_septet_pack2;
 gsm_septets2octets;
 
 lapd_dl_exit;
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/tests/gsm0808/gsm0808_test.c 
new/libosmocore-1.14.2/tests/gsm0808/gsm0808_test.c
--- old/libosmocore-1.14.1/tests/gsm0808/gsm0808_test.c 2026-07-22 
12:35:06.000000000 +0200
+++ new/libosmocore-1.14.2/tests/gsm0808/gsm0808_test.c 2026-08-21 
07:20:41.000000000 +0200
@@ -1281,10 +1281,42 @@
 
        rc_dec = gsm0808_dec_encrypt_info(&dec_ei, msg->data + 2, msg->len - 2);
        OSMO_ASSERT(rc_dec == 9);
-
        OSMO_ASSERT(memcmp(&enc_ei, &dec_ei, sizeof(enc_ei)) == 0);
 
+
+       /* Test decoding IE with No Encryption and hence with no Key */
+       struct gsm0808_encrypt_info enc_ei_no_encryption = {
+               .perm_algo = { GSM0808_ALG_ID_A5_0 },
+               .perm_algo_len = 1,
+               .key = { 0 },
+               .key_len = 0,
+       };
+       uint8_t ei_enc_no_encryption_expected[] = { 
GSM0808_IE_ENCRYPTION_INFORMATION, 0x01, 0x01 };
+
+       msg = msgb_alloc(1024, "output buffer");
+       rc_enc = gsm0808_enc_encrypt_info(msg, &enc_ei_no_encryption);
+       OSMO_ASSERT(rc_enc == 3);
+       OSMO_ASSERT(memcmp(ei_enc_no_encryption_expected, msg->data, msg->len) 
== 0);
+
+       rc_dec = gsm0808_dec_encrypt_info(&dec_ei, msg->data + 2, msg->len - 2);
+       OSMO_ASSERT(rc_dec == 1);
+       OSMO_ASSERT(memcmp(&enc_ei_no_encryption, &dec_ei, 
sizeof(enc_ei_no_encryption)) == 0);
        msgb_free(msg);
+
+       /* Test decoding of malformed IE with no algo selected: */
+       uint8_t ei_enc_no_algo[] = { GSM0808_IE_ENCRYPTION_INFORMATION, 0x01, 
0x00 };
+       rc_dec = gsm0808_dec_encrypt_info(&dec_ei, &ei_enc_no_algo[2], 
sizeof(ei_enc_no_algo) - 2);
+       OSMO_ASSERT(rc_dec == -EINVAL);
+
+       /* Test decoding of malformed IE with wrong key length: */
+       uint8_t ei_enc_wrong_key_len[256] = { 
GSM0808_IE_ENCRYPTION_INFORMATION, 0xfd, 0x03 };
+       rc_dec = gsm0808_dec_encrypt_info(&dec_ei, &ei_enc_wrong_key_len[2], 
0xfd);
+       OSMO_ASSERT(rc_dec == -EINVAL);
+       /* test with another invalid key length: */
+       ei_enc_wrong_key_len[1] = 0x03;
+       rc_dec = gsm0808_dec_encrypt_info(&dec_ei, &ei_enc_wrong_key_len[2], 
0x03);
+       OSMO_ASSERT(rc_dec == -EINVAL);
+
 }
 
 static void test_gsm0808_dec_cell_id_list_srvcc(void)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/tests/gsm29205/gsm29205_test.c 
new/libosmocore-1.14.2/tests/gsm29205/gsm29205_test.c
--- old/libosmocore-1.14.1/tests/gsm29205/gsm29205_test.c       2026-07-22 
12:35:06.000000000 +0200
+++ new/libosmocore-1.14.2/tests/gsm29205/gsm29205_test.c       2026-08-21 
07:20:41.000000000 +0200
@@ -95,6 +95,34 @@
        msgb_free(msg);
 }
 
+/* osmo_dec_gcr() must reject buffers that are too short for the announced
+ * .net_len (3..5), not just shorter than the 13-byte minimum for
+ * .net_len == 3.  Otherwise it reads past the end of 'elem'. */
+static void test_gcr_dec_short_buf(void)
+{
+       static const uint8_t res[] = {
+               0x05, /* .net_len */
+               0x51, 0x52, 0x53, 0x54, 0x55, /* .net */
+               0x02, /* .node length */
+               0xde, 0xad, /* .node */
+               0x05, /* length of Call. Ref. */
+               0x41, 0x42, 0x43, 0x44, 0x45 /* .cr - Call. Ref. */
+       };
+       struct osmo_gcr_parsed p;
+       uint8_t len;
+       int rc;
+
+       printf("Testing Global Call Reference decoder against short 
buffers...\n");
+
+       /* net_len == 5 requires 15 bytes, feed it 13 and 14
+        * the full buffer must still decode successfully */
+       for (len = 13; len <= ARRAY_SIZE(res); len++) {
+               rc = osmo_dec_gcr(&p, res, len);
+               printf("\tosmo_dec_gcr(len=%u) -> %s\n",
+                      len, rc == len ? "OK" : "FAIL");
+       }
+}
+
 int main(int argc, char **argv)
 {
        osmo_init_logging2(talloc_named_const(NULL, 0, "gsm29205 test"), NULL);
@@ -102,6 +130,7 @@
        printf("Testing 3GPP TS 29.205 routines...\n");
 
        test_gcr();
+       test_gcr_dec_short_buf();
 
        printf("Done.\n");
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/tests/gsm29205/gsm29205_test.ok 
new/libosmocore-1.14.2/tests/gsm29205/gsm29205_test.ok
--- old/libosmocore-1.14.1/tests/gsm29205/gsm29205_test.ok      2026-07-22 
12:35:06.000000000 +0200
+++ new/libosmocore-1.14.2/tests/gsm29205/gsm29205_test.ok      2026-08-21 
07:20:41.000000000 +0200
@@ -2,4 +2,8 @@
 Testing Global Call Reference encoder...
        13 bytes added: OK
        decoded 13 bytes: OK
+Testing Global Call Reference decoder against short buffers...
+       osmo_dec_gcr(len=13) -> FAIL
+       osmo_dec_gcr(len=14) -> FAIL
+       osmo_dec_gcr(len=15) -> OK
 Done.
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/tests/iuup/iuup_test.c 
new/libosmocore-1.14.2/tests/iuup/iuup_test.c
--- old/libosmocore-1.14.1/tests/iuup/iuup_test.c       2026-07-22 
12:35:06.000000000 +0200
+++ new/libosmocore-1.14.2/tests/iuup/iuup_test.c       2026-08-21 
07:20:41.000000000 +0200
@@ -31,6 +31,56 @@
        .t_rc = { .t_ms = IUUP_TIMER_RC_T_DEFAULT, .n_max = 
IUUP_TIMER_RC_N_DEFAULT },
 };
 
+/*  Frame 46, "Initialization",  SYS#5969 call4_Iu_Iuh.pcap
+       1110 .... = PDU Type: Control Procedure (14)
+       .... 00.. = Ack/Nack: Procedure (0)
+       .... ..00 = Frame Number: 0
+       0000 .... = Mode Version: 0x0
+       .... 0000 = Procedure: Initialization (0)
+       1101 11.. = Header CRC: 0x37 [correct]
+       .... ..01 1011 0100 = Payload CRC: 0x1b4
+       000. .... = Spare: 0x0
+       ...0 .... = TI: IPTIs not present (0)
+       .... 011. = Subflows: 3
+       .... ...0 = Chain Indicator: this frame is the last frame for the 
procedure (0)
+       RFCI 1 Initialization
+       0... .... = RFCI 0 LRI: Not last RFCI (0x0)
+       .0.. .... = RFCI 0 LI: one octet used (0x0)
+       ..00 0001 = RFCI 0: 1
+       RFCI 0 Flow 0 Len: 81
+       RFCI 0 Flow 1 Len: 103
+       RFCI 0 Flow 2 Len: 60
+       RFCI 6 Initialization
+       1... .... = RFCI 1 LRI: Last RFCI in current frame (0x1)
+       .0.. .... = RFCI 1 LI: one octet used (0x0)
+       ..00 0110 = RFCI 1: 6
+       RFCI 1 Flow 0 Len: 39
+       RFCI 1 Flow 1 Len: 0
+       RFCI 1 Flow 2 Len: 0
+       Iu UP Mode Versions Supported: 0x0001
+       0... .... .... .... = Version 16: not supported (0x0)
+       .0.. .... .... .... = Version 15: not supported (0x0)
+       ..0. .... .... .... = Version 14: not supported (0x0)
+       ...0 .... .... .... = Version 13: not supported (0x0)
+       .... 0... .... .... = Version 12: not supported (0x0)
+       .... .0.. .... .... = Version 11: not supported (0x0)
+       .... ..0. .... .... = Version 10: not supported (0x0)
+       .... ...0 .... .... = Version  9: not supported (0x0)
+       .... .... 0... .... = Version  8: not supported (0x0)
+       .... .... .0.. .... = Version  7: not supported (0x0)
+       .... .... ..0. .... = Version  6: not supported (0x0)
+       .... .... ...0 .... = Version  5: not supported (0x0)
+       .... .... .... 0... = Version  4: not supported (0x0)
+       .... .... .... .0.. = Version  3: not supported (0x0)
+       .... .... .... ..0. = Version  2: not supported (0x0)
+       .... .... .... ...1 = Version  1: supported (0x1)
+       0000 .... = RFCI Data Pdu Type: PDU type 0 (0x0)
+*/
+const uint8_t iuup_initialization_no_iptis[] = {
+       0xe0, 0x00, 0xdd, 0xb4, 0x06, 0x01, 0x51, 0x67, 0x3c, 0x86, 0x27,
+       0x00, 0x00, 0x00, 0x01, 0x00
+};
+
 /*  Frame 33, "Initialization",  OS#4744 3g_call_23112021.pcapng
 IuUP
        1110 .... = PDU Type: Control Procedure (14)
@@ -665,56 +715,6 @@
        struct iuup_pdutype14_hdr *hdr14;
        int rc;
 
-       /*  Frame 46, "Initialization",  SYS#5969 call4_Iu_Iuh.pcap
-       1110 .... = PDU Type: Control Procedure (14)
-       .... 00.. = Ack/Nack: Procedure (0)
-       .... ..00 = Frame Number: 0
-       0000 .... = Mode Version: 0x0
-       .... 0000 = Procedure: Initialization (0)
-       1101 11.. = Header CRC: 0x37 [correct]
-       .... ..01 1011 0100 = Payload CRC: 0x1b4
-       000. .... = Spare: 0x0
-       ...0 .... = TI: IPTIs not present (0)
-       .... 011. = Subflows: 3
-       .... ...0 = Chain Indicator: this frame is the last frame for the 
procedure (0)
-       RFCI 1 Initialization
-       0... .... = RFCI 0 LRI: Not last RFCI (0x0)
-       .0.. .... = RFCI 0 LI: one octet used (0x0)
-       ..00 0001 = RFCI 0: 1
-       RFCI 0 Flow 0 Len: 81
-       RFCI 0 Flow 1 Len: 103
-       RFCI 0 Flow 2 Len: 60
-       RFCI 6 Initialization
-       1... .... = RFCI 1 LRI: Last RFCI in current frame (0x1)
-       .0.. .... = RFCI 1 LI: one octet used (0x0)
-       ..00 0110 = RFCI 1: 6
-       RFCI 1 Flow 0 Len: 39
-       RFCI 1 Flow 1 Len: 0
-       RFCI 1 Flow 2 Len: 0
-       Iu UP Mode Versions Supported: 0x0001
-       0... .... .... .... = Version 16: not supported (0x0)
-       .0.. .... .... .... = Version 15: not supported (0x0)
-       ..0. .... .... .... = Version 14: not supported (0x0)
-       ...0 .... .... .... = Version 13: not supported (0x0)
-       .... 0... .... .... = Version 12: not supported (0x0)
-       .... .0.. .... .... = Version 11: not supported (0x0)
-       .... ..0. .... .... = Version 10: not supported (0x0)
-       .... ...0 .... .... = Version  9: not supported (0x0)
-       .... .... 0... .... = Version  8: not supported (0x0)
-       .... .... .0.. .... = Version  7: not supported (0x0)
-       .... .... ..0. .... = Version  6: not supported (0x0)
-       .... .... ...0 .... = Version  5: not supported (0x0)
-       .... .... .... 0... = Version  4: not supported (0x0)
-       .... .... .... .0.. = Version  3: not supported (0x0)
-       .... .... .... ..0. = Version  2: not supported (0x0)
-       .... .... .... ...1 = Version  1: supported (0x1)
-       0000 .... = RFCI Data Pdu Type: PDU type 0 (0x0)
-       */
-       const uint8_t iuup_init[] = {
-               0xe0, 0x00, 0xdd, 0xb4, 0x06, 0x01, 0x51, 0x67, 0x3c, 0x86, 
0x27,
-               0x00, 0x00, 0x00, 0x01, 0x00
-       };
-
        iui = osmo_iuup_instance_alloc(iuup_test_ctx, __func__);
        OSMO_ASSERT(iui);
        osmo_iuup_instance_set_user_prim_cb(iui, 
_decode_passive_init_2_rfci_no_iptis_user_prim_cb, NULL);
@@ -732,15 +732,226 @@
 
        /* Send Init: */
        tnp = osmo_iuup_tnl_prim_alloc(iuup_test_ctx, OSMO_IUUP_TNL_UNITDATA, 
PRIM_OP_INDICATION, IUUP_MSGB_SIZE);
-       tnp->oph.msg->l2h = msgb_put(tnp->oph.msg, sizeof(iuup_init));
+       tnp->oph.msg->l2h = msgb_put(tnp->oph.msg, 
sizeof(iuup_initialization_no_iptis));
+       hdr14 = (struct iuup_pdutype14_hdr *)msgb_l2(tnp->oph.msg);
+       memcpy(hdr14, iuup_initialization_no_iptis, 
sizeof(iuup_initialization_no_iptis));
+
+       rc = osmo_iuup_tnl_prim_up(iui, tnp);
+       OSMO_ASSERT(rc == 0);
+
+       osmo_iuup_instance_free(iui);
+}
+
+static int _decode_passive_init_exp_nack_transport_prim_cb(struct 
osmo_prim_hdr *oph, void *ctx)
+{
+       struct osmo_iuup_tnl_prim *itp = (struct osmo_iuup_tnl_prim *)oph;
+       struct msgb *msg;
+       struct iuup_pdutype14_hdr *hdr;
+
+       printf("%s()\n", __func__);
+       msg = oph->msg;
+       OSMO_ASSERT(OSMO_PRIM_HDR(&itp->oph) == 
OSMO_PRIM(OSMO_IUUP_TNL_UNITDATA, PRIM_OP_REQUEST));
+       printf("Transport: DL len=%u: %s\n", msgb_l2len(msg),
+              osmo_hexdump((const unsigned char *) msgb_l2(msg), 
msgb_l2len(msg)));
+       hdr = msgb_l2(msg);
+       OSMO_ASSERT(hdr->pdu_type == IUUP_PDU_T_CONTROL);
+       OSMO_ASSERT(hdr->ack_nack == IUUP_AN_NACK);
+       msgb_free(msg);
+       return 0;
+}
+/* Send a malformed Initialization to UIT containing num_subflows_per_rfci = 0.
+ * It shall be rejected since num_subflows_per_rfci should be at least one 
accoridng to 3GPP TS 25.415 Figure 24 */
+void test_decode_passive_init_malformed_0subflows(void)
+{
+       /* Here we check the passive INIT code path, aka receiving INIT and 
returning INIT_ACK/NACK */
+       struct osmo_iuup_instance *iui;
+       struct osmo_iuup_rnl_prim *rnp;
+       struct osmo_iuup_tnl_prim *tnp;
+       struct iuup_pdutype14_hdr *hdr14;
+       struct iuup_ctrl_init_hdr *ihdr;
+       uint16_t payload_crc;
+       int rc;
+
+       iui = osmo_iuup_instance_alloc(iuup_test_ctx, __func__);
+       OSMO_ASSERT(iui);
+       osmo_iuup_instance_set_transport_prim_cb(iui, 
_decode_passive_init_exp_nack_transport_prim_cb, NULL);
+
+       clock_override_set(0, 0);
+
+       /* Tx CONFIG.req */
+       rnp = osmo_iuup_rnl_prim_alloc(iuup_test_ctx, OSMO_IUUP_RNL_CONFIG, 
PRIM_OP_REQUEST, IUUP_MSGB_SIZE);
+       rnp->u.config = def_configure_req;
+       rnp->u.config.active = false;
+
+       rc = osmo_iuup_rnl_prim_down(iui, rnp);
+       OSMO_ASSERT(rc == 0);
+
+       /* Prepare and send Init: copy iuup_initialization_no_iptis, modify 
setting TI=1 (becoming malformed) and dispatch it. */
+       tnp = osmo_iuup_tnl_prim_alloc(iuup_test_ctx, OSMO_IUUP_TNL_UNITDATA, 
PRIM_OP_INDICATION, IUUP_MSGB_SIZE);
+       tnp->oph.msg->l2h = msgb_put(tnp->oph.msg, 
sizeof(iuup_initialization_no_iptis));
+       hdr14 = (struct iuup_pdutype14_hdr *)msgb_l2(tnp->oph.msg);
+       memcpy(hdr14, iuup_initialization_no_iptis, 
sizeof(iuup_initialization_no_iptis));
+
+       ihdr = (struct iuup_ctrl_init_hdr *)hdr14->payload;
+       ihdr->num_subflows_per_rfci = 0;
+       payload_crc = osmo_iuup_compute_payload_crc(msgb_l2(tnp->oph.msg), 
msgb_l2len(tnp->oph.msg));
+       hdr14->payload_crc_hi = (payload_crc >> 8) & 0x03;
+       hdr14->payload_crc_lo = payload_crc & 0xff;
+
+       rc = osmo_iuup_tnl_prim_up(iui, tnp);
+       OSMO_ASSERT(rc == 0);
+
+       osmo_iuup_instance_free(iui);
+}
+
+/* Send a malformed Initialization to UIT containing TI=1 and no IPTIs encoded.
+ * As a result, the msgb content is too short and should be rejected. */
+void test_decode_passive_init_malformed_ti1_no_iptis(void)
+{
+       /* Here we check the passive INIT code path, aka receiving INIT and 
returning INIT_ACK/NACK */
+       struct osmo_iuup_instance *iui;
+       struct osmo_iuup_rnl_prim *rnp;
+       struct osmo_iuup_tnl_prim *tnp;
+       struct iuup_pdutype14_hdr *hdr14;
+       struct iuup_ctrl_init_hdr *ihdr;
+       uint16_t payload_crc;
+       int rc;
+
+       iui = osmo_iuup_instance_alloc(iuup_test_ctx, __func__);
+       OSMO_ASSERT(iui);
+       osmo_iuup_instance_set_transport_prim_cb(iui, 
_decode_passive_init_exp_nack_transport_prim_cb, NULL);
+
+       clock_override_set(0, 0);
+
+       /* Tx CONFIG.req */
+       rnp = osmo_iuup_rnl_prim_alloc(iuup_test_ctx, OSMO_IUUP_RNL_CONFIG, 
PRIM_OP_REQUEST, IUUP_MSGB_SIZE);
+       rnp->u.config = def_configure_req;
+       rnp->u.config.active = false;
+
+       rc = osmo_iuup_rnl_prim_down(iui, rnp);
+       OSMO_ASSERT(rc == 0);
+
+       /* Prepare and send Init: copy iuup_initialization_no_iptis, modify 
setting TI=1 (becoming malformed) and dispatch it. */
+       tnp = osmo_iuup_tnl_prim_alloc(iuup_test_ctx, OSMO_IUUP_TNL_UNITDATA, 
PRIM_OP_INDICATION, IUUP_MSGB_SIZE);
+       tnp->oph.msg->l2h = msgb_put(tnp->oph.msg, 
sizeof(iuup_initialization_no_iptis));
+       hdr14 = (struct iuup_pdutype14_hdr *)msgb_l2(tnp->oph.msg);
+       memcpy(hdr14, iuup_initialization_no_iptis, 
sizeof(iuup_initialization_no_iptis));
+
+       ihdr = (struct iuup_ctrl_init_hdr *)hdr14->payload;
+       ihdr->ti = 1;
+       payload_crc = osmo_iuup_compute_payload_crc(msgb_l2(tnp->oph.msg), 
msgb_l2len(tnp->oph.msg));
+       hdr14->payload_crc_hi = (payload_crc >> 8) & 0x03;
+       hdr14->payload_crc_lo = payload_crc & 0xff;
+
+       rc = osmo_iuup_tnl_prim_up(iui, tnp);
+       OSMO_ASSERT(rc == 0);
+
+       osmo_iuup_instance_free(iui);
+}
+
+/* Send a malformed Initialization to UIT containing no RFCIs.
+ * As a result, the msgb content is too short and should be rejected. */
+void _test_submit_iuup_initialization_trimmed(unsigned int pkt_len, const char 
*test_name)
+{
+       /* Here we check the passive INIT code path, aka receiving INIT and 
returning INIT_ACK/NACK */
+       struct osmo_iuup_instance *iui;
+       struct osmo_iuup_rnl_prim *rnp;
+       struct osmo_iuup_tnl_prim *tnp;
+       struct iuup_pdutype14_hdr *hdr14;
+       uint16_t payload_crc;
+       int rc;
+
+       OSMO_ASSERT(pkt_len <= sizeof(iuup_initialization_no_iptis));
+
+       iui = osmo_iuup_instance_alloc(iuup_test_ctx, test_name);
+       OSMO_ASSERT(iui);
+       osmo_iuup_instance_set_transport_prim_cb(iui, 
_decode_passive_init_exp_nack_transport_prim_cb, NULL);
+
+       /* Tx CONFIG.req */
+       rnp = osmo_iuup_rnl_prim_alloc(iuup_test_ctx, OSMO_IUUP_RNL_CONFIG, 
PRIM_OP_REQUEST, IUUP_MSGB_SIZE);
+       rnp->u.config = def_configure_req;
+       rnp->u.config.active = false;
+
+       rc = osmo_iuup_rnl_prim_down(iui, rnp);
+       OSMO_ASSERT(rc == 0);
+
+       /* Prepare and send Init: copy iuup_initialization_no_iptis, modify 
setting TI=1 (becoming malformed) and dispatch it. */
+       tnp = osmo_iuup_tnl_prim_alloc(iuup_test_ctx, OSMO_IUUP_TNL_UNITDATA, 
PRIM_OP_INDICATION, IUUP_MSGB_SIZE);
+       tnp->oph.msg->l2h = msgb_put(tnp->oph.msg, pkt_len);
        hdr14 = (struct iuup_pdutype14_hdr *)msgb_l2(tnp->oph.msg);
-       memcpy(hdr14, iuup_init, sizeof(iuup_init));
+       memcpy(hdr14, iuup_initialization_no_iptis, pkt_len);
+
+       payload_crc = osmo_iuup_compute_payload_crc(msgb_l2(tnp->oph.msg), 
msgb_l2len(tnp->oph.msg));
+       hdr14->payload_crc_hi = (payload_crc >> 8) & 0x03;
+       hdr14->payload_crc_lo = payload_crc & 0xff;
 
        rc = osmo_iuup_tnl_prim_up(iui, tnp);
        OSMO_ASSERT(rc == 0);
 
        osmo_iuup_instance_free(iui);
 }
+void test_decode_passive_init_malformed_no_rfci(void)
+{
+       unsigned int pkt_len = sizeof(struct iuup_pdutype14_hdr) + 
sizeof(struct iuup_ctrl_init_hdr);
+       clock_override_set(0, 0);
+       _test_submit_iuup_initialization_trimmed(pkt_len, __func__);
+}
+
+/* Send a malformed Initialization to UIT containing malformed RFCIs.
+ * As a result, the msgb content is too short and should be rejected. */
+void test_decode_passive_init_malformed_rfci_too_short(void)
+{
+       unsigned int pkt_len = sizeof(struct iuup_pdutype14_hdr) + 
sizeof(struct iuup_ctrl_init_hdr) + 2;
+       clock_override_set(0, 0);
+       _test_submit_iuup_initialization_trimmed(pkt_len, __func__);
+}
+
+void test_decode_passive_init_malformed_missing_last_byte(void)
+{
+       clock_override_set(0, 0);
+       
_test_submit_iuup_initialization_trimmed(sizeof(iuup_initialization_no_iptis) - 
1, __func__);
+}
+
+/* Test IUT when a way too big IuUP data packet is received. It should be 
dropped. */
+void test_data_too_big(void)
+{
+       /* Here we check the passive INIT code path, aka receiving INIT and 
returning INIT_ACK/NACK */
+       struct osmo_iuup_instance *iui;
+       struct osmo_iuup_rnl_prim *rnp;
+       struct osmo_iuup_tnl_prim *tnp;
+       struct iuup_pdutype0_hdr *hdr0;
+       uint16_t payload_crc;
+       int rc;
+       unsigned int pkt_len = sizeof(struct iuup_pdutype0_hdr) + 1600;
+       OSMO_ASSERT(pkt_len <= IUUP_MSGB_SIZE);
+
+       iui = osmo_iuup_instance_alloc(iuup_test_ctx, __func__);
+       OSMO_ASSERT(iui);
+
+       clock_override_set(0, 0);
+
+       /* Tx CONFIG.req */
+       rnp = osmo_iuup_rnl_prim_alloc(iuup_test_ctx, OSMO_IUUP_RNL_CONFIG, 
PRIM_OP_REQUEST, IUUP_MSGB_SIZE);
+       rnp->u.config = def_configure_req;
+       rnp->u.config.active = false;
+
+       rc = osmo_iuup_rnl_prim_down(iui, rnp);
+       OSMO_ASSERT(rc == 0);
+
+       /* Send IuUP incoming data to the implementation: */
+       tnp = osmo_iuup_tnl_prim_alloc(iuup_test_ctx, OSMO_IUUP_TNL_UNITDATA, 
PRIM_OP_INDICATION, IUUP_MSGB_SIZE);
+       tnp->oph.msg->l2h = msgb_put(tnp->oph.msg, pkt_len);
+       hdr0 = (struct iuup_pdutype0_hdr *)msgb_l2(tnp->oph.msg);
+       memcpy(hdr0, iuup_data, sizeof(iuup_data));
+
+       payload_crc = osmo_iuup_compute_payload_crc(msgb_l2(tnp->oph.msg), 
msgb_l2len(tnp->oph.msg));
+       hdr0->payload_crc_hi = (payload_crc >> 8) & 0x03;
+       hdr0->payload_crc_lo = payload_crc & 0xff;
+
+       OSMO_ASSERT((rc = osmo_iuup_tnl_prim_up(iui, tnp)) == 0);
+
+       osmo_iuup_instance_free(iui);
+}
 
 int main(int argc, char **argv)
 {
@@ -762,6 +973,12 @@
        test_passive_init();
        test_passive_init_retrans();
        test_decode_passive_init_2_rfci_no_iptis();
+       test_decode_passive_init_malformed_0subflows();
+       test_decode_passive_init_malformed_ti1_no_iptis();
+       test_decode_passive_init_malformed_no_rfci();
+       test_decode_passive_init_malformed_rfci_too_short();
+       test_decode_passive_init_malformed_missing_last_byte();
+       test_data_too_big();
 
        printf("OK.\n");
 }
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/tests/iuup/iuup_test.err 
new/libosmocore-1.14.2/tests/iuup/iuup_test.err
--- old/libosmocore-1.14.1/tests/iuup/iuup_test.err     2026-07-22 
12:35:06.000000000 +0200
+++ new/libosmocore-1.14.2/tests/iuup/iuup_test.err     2026-08-21 
07:20:41.000000000 +0200
@@ -53,3 +53,43 @@
 DLIUUP IuUP(test_decode_passive_init_2_rfci_no_iptis){Initialisation}: Tx 
Initialization ACK
 DLIUUP IuUP(test_decode_passive_init_2_rfci_no_iptis){Initialisation}: 
state_chg to SMpSDU_Data_Transfer_Ready
 DLIUUP 
IuUP(test_decode_passive_init_2_rfci_no_iptis){SMpSDU_Data_Transfer_Ready}: 
Deallocated
+DLIUUP IuUP(test_decode_passive_init_malformed_0subflows){NULL}: Allocated
+DLIUUP IuUP(test_decode_passive_init_malformed_0subflows){NULL}: Received 
Event IuUP-CONFIG-req
+DLIUUP IuUP(test_decode_passive_init_malformed_0subflows){NULL}: state_chg to 
Initialisation
+DLIUUP IuUP(test_decode_passive_init_malformed_0subflows){Initialisation}: 
Received Event INIT
+DLIUUP IuUP(test_decode_passive_init_malformed_0subflows){Initialisation}: 
Initialization: Unexpected num_subflows=0 received
+DLIUUP IuUP(test_decode_passive_init_malformed_0subflows){Initialisation}: Tx 
Initialization NACK cause=20 orig_message=e0 00 dc 62 00 01 51 67 3c 86 27 00 
00 00 01 00 
+DLIUUP IuUP(test_decode_passive_init_malformed_0subflows){Initialisation}: 
Deallocated
+DLIUUP IuUP(test_decode_passive_init_malformed_ti1_no_iptis){NULL}: Allocated
+DLIUUP IuUP(test_decode_passive_init_malformed_ti1_no_iptis){NULL}: Received 
Event IuUP-CONFIG-req
+DLIUUP IuUP(test_decode_passive_init_malformed_ti1_no_iptis){NULL}: state_chg 
to Initialisation
+DLIUUP IuUP(test_decode_passive_init_malformed_ti1_no_iptis){Initialisation}: 
Received Event INIT
+DLIUUP IuUP(test_decode_passive_init_malformed_ti1_no_iptis){Initialisation}: 
Initialization: Malformed packet, length 16 too short
+DLIUUP IuUP(test_decode_passive_init_malformed_ti1_no_iptis){Initialisation}: 
Tx Initialization NACK cause=8 orig_message=e0 00 dc 06 16 01 51 67 3c 86 27 00 
00 00 01 00 
+DLIUUP IuUP(test_decode_passive_init_malformed_ti1_no_iptis){Initialisation}: 
Deallocated
+DLIUUP IuUP(test_decode_passive_init_malformed_no_rfci){NULL}: Allocated
+DLIUUP IuUP(test_decode_passive_init_malformed_no_rfci){NULL}: Received Event 
IuUP-CONFIG-req
+DLIUUP IuUP(test_decode_passive_init_malformed_no_rfci){NULL}: state_chg to 
Initialisation
+DLIUUP IuUP(test_decode_passive_init_malformed_no_rfci){Initialisation}: 
Received Event INIT
+DLIUUP IuUP(test_decode_passive_init_malformed_no_rfci){Initialisation}: 
Initialization: Malformed packet, length 5 too short
+DLIUUP IuUP(test_decode_passive_init_malformed_no_rfci){Initialisation}: Tx 
Initialization NACK cause=8 orig_message=e0 00 dc cc 06 
+DLIUUP IuUP(test_decode_passive_init_malformed_no_rfci){Initialisation}: 
Deallocated
+DLIUUP IuUP(test_decode_passive_init_malformed_rfci_too_short){NULL}: Allocated
+DLIUUP IuUP(test_decode_passive_init_malformed_rfci_too_short){NULL}: Received 
Event IuUP-CONFIG-req
+DLIUUP IuUP(test_decode_passive_init_malformed_rfci_too_short){NULL}: 
state_chg to Initialisation
+DLIUUP 
IuUP(test_decode_passive_init_malformed_rfci_too_short){Initialisation}: 
Received Event INIT
+DLIUUP 
IuUP(test_decode_passive_init_malformed_rfci_too_short){Initialisation}: 
Initialization: Malformed packet, length 7 too short
+DLIUUP 
IuUP(test_decode_passive_init_malformed_rfci_too_short){Initialisation}: Tx 
Initialization NACK cause=8 orig_message=e0 00 df 7d 06 01 51 
+DLIUUP 
IuUP(test_decode_passive_init_malformed_rfci_too_short){Initialisation}: 
Deallocated
+DLIUUP IuUP(test_decode_passive_init_malformed_missing_last_byte){NULL}: 
Allocated
+DLIUUP IuUP(test_decode_passive_init_malformed_missing_last_byte){NULL}: 
Received Event IuUP-CONFIG-req
+DLIUUP IuUP(test_decode_passive_init_malformed_missing_last_byte){NULL}: 
state_chg to Initialisation
+DLIUUP 
IuUP(test_decode_passive_init_malformed_missing_last_byte){Initialisation}: 
Received Event INIT
+DLIUUP 
IuUP(test_decode_passive_init_malformed_missing_last_byte){Initialisation}: 
Initialization: Malformed packet, length 15 too short
+DLIUUP 
IuUP(test_decode_passive_init_malformed_missing_last_byte){Initialisation}: Tx 
Initialization NACK cause=8 orig_message=e0 00 df f7 06 01 51 67 3c 86 27 00 00 
00 01 
+DLIUUP 
IuUP(test_decode_passive_init_malformed_missing_last_byte){Initialisation}: 
Deallocated
+DLIUUP IuUP(test_data_too_big){NULL}: Allocated
+DLIUUP IuUP(test_data_too_big){NULL}: Received Event IuUP-CONFIG-req
+DLIUUP IuUP(test_data_too_big){NULL}: state_chg to Initialisation
+DLIUUP Payload Checksum failed (pdu type 0): Packet too big? length 1604
+DLIUUP IuUP(test_data_too_big){Initialisation}: Discarding invalid IuUP PDU: 
01 00 e3 ff 08 55 6d 94 4c 71 a1 a0 81 e7 ea d2 04 24 44 80 00 0e cd 82 b8 11 
18 00 00 97 c4 79 4e 77 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
 0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 0DLIUUP IuUP(test_data_too_big){Initialisation}: 
Deallocated
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/tests/iuup/iuup_test.ok 
new/libosmocore-1.14.2/tests/iuup/iuup_test.ok
--- old/libosmocore-1.14.1/tests/iuup/iuup_test.ok      2026-07-22 
12:35:06.000000000 +0200
+++ new/libosmocore-1.14.2/tests/iuup/iuup_test.ok      2026-08-21 
07:20:41.000000000 +0200
@@ -58,4 +58,20 @@
 _decode_passive_init_2_rfci_no_iptis_user_prim_cb(): Initialization decoded 
fine!
 _decode_passive_init_2_rfci_no_iptis_transport_prim_cb()
 Transport: DL len=4: e4 00 24 00 
+sys={0.000000}, clock_override_set
+_decode_passive_init_exp_nack_transport_prim_cb()
+Transport: DL len=5: e8 00 90 00 50 
+sys={0.000000}, clock_override_set
+_decode_passive_init_exp_nack_transport_prim_cb()
+Transport: DL len=5: e8 00 90 00 20 
+sys={0.000000}, clock_override_set
+_decode_passive_init_exp_nack_transport_prim_cb()
+Transport: DL len=5: e8 00 90 00 20 
+sys={0.000000}, clock_override_set
+_decode_passive_init_exp_nack_transport_prim_cb()
+Transport: DL len=5: e8 00 90 00 20 
+sys={0.000000}, clock_override_set
+_decode_passive_init_exp_nack_transport_prim_cb()
+Transport: DL len=5: e8 00 90 00 20 
+sys={0.000000}, clock_override_set
 OK.
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/libosmocore-1.14.1/tests/osmo-config-merge/package.m4 
new/libosmocore-1.14.2/tests/osmo-config-merge/package.m4
--- old/libosmocore-1.14.1/tests/osmo-config-merge/package.m4   2026-07-22 
12:35:26.000000000 +0200
+++ new/libosmocore-1.14.2/tests/osmo-config-merge/package.m4   2026-08-21 
07:21:04.000000000 +0200
@@ -4,9 +4,9 @@
 m4_define([AT_PACKAGE_TARNAME],
   [libosmocore])
 m4_define([AT_PACKAGE_VERSION],
-  [1.14.1])
+  [1.14.2])
 m4_define([AT_PACKAGE_STRING],
-  [libosmocore 1.14.1])
+  [libosmocore 1.14.2])
 m4_define([AT_PACKAGE_BUGREPORT],
   [[email protected]])
 m4_define([AT_PACKAGE_URL],
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/tests/osmo-config-merge/testsuite 
new/libosmocore-1.14.2/tests/osmo-config-merge/testsuite
--- old/libosmocore-1.14.1/tests/osmo-config-merge/testsuite    2026-07-22 
12:35:27.000000000 +0200
+++ new/libosmocore-1.14.2/tests/osmo-config-merge/testsuite    2026-08-21 
07:21:04.000000000 +0200
@@ -923,7 +923,7 @@
 # List of tests.
 if $at_list_p; then
   cat <<_ATEOF || at_write_fail=1
-libosmocore 1.14.1 test suite test groups:
+libosmocore 1.14.2 test suite test groups:
 
  NUM: FILE-NAME:LINE     TEST-GROUP-NAME
       KEYWORDS
@@ -964,7 +964,7 @@
   exit $at_write_fail
 fi
 if $at_version_p; then
-  printf "%s\n" "$as_me (libosmocore 1.14.1)" &&
+  printf "%s\n" "$as_me (libosmocore 1.14.2)" &&
   cat <<\_ATEOF || at_write_fail=1
 
 Copyright (C) 2021 Free Software Foundation, Inc.
@@ -1152,11 +1152,11 @@
 
 # Banners and logs.
 printf "%s\n" "## ------------------------------ ##
-## libosmocore 1.14.1 test suite. ##
+## libosmocore 1.14.2 test suite. ##
 ## ------------------------------ ##"
 {
   printf "%s\n" "## ------------------------------ ##
-## libosmocore 1.14.1 test suite. ##
+## libosmocore 1.14.2 test suite. ##
 ## ------------------------------ ##"
   echo
 
@@ -1973,7 +1973,7 @@
   printf "%s\n" "Please send $at_msg and all information you think might help:
 
    To: <[email protected]>
-   Subject: [libosmocore 1.14.1] $as_me: $at_msg1$at_msg2
+   Subject: [libosmocore 1.14.2] $as_me: $at_msg1$at_msg2
 
 You may investigate any problem if you feel able to do so, in which
 case the test suite provides a good starting point.  Its output may
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/libosmocore-1.14.1/tests/osmo_io/osmo_io_backpressure_test.c 
new/libosmocore-1.14.2/tests/osmo_io/osmo_io_backpressure_test.c
--- old/libosmocore-1.14.1/tests/osmo_io/osmo_io_backpressure_test.c    
2026-07-22 12:35:06.000000000 +0200
+++ new/libosmocore-1.14.2/tests/osmo_io/osmo_io_backpressure_test.c    
2026-08-21 07:20:41.000000000 +0200
@@ -106,7 +106,6 @@
        file_bytes_write_compl = 0;
 
        char drain_buffer[512];
-       int messages_queued = 0;
 
        for (int i = 0; i < 10; i++) {
                /* Add a message */
@@ -114,9 +113,7 @@
                memset(msgb_put(msg, 1024), 0xAA + (i % 16), 1024);
 
                rc = osmo_iofd_write_msgb(iofd, msg);
-               if (rc == 0)
-                       messages_queued++;
-               else
+               if (rc != 0)
                        msgb_free(msg);
 
                /* Process events with explicit timeout */
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/tests/package.m4 
new/libosmocore-1.14.2/tests/package.m4
--- old/libosmocore-1.14.1/tests/package.m4     2026-07-22 12:35:26.000000000 
+0200
+++ new/libosmocore-1.14.2/tests/package.m4     2026-08-21 07:21:04.000000000 
+0200
@@ -4,9 +4,9 @@
 m4_define([AT_PACKAGE_TARNAME],
   [libosmocore])
 m4_define([AT_PACKAGE_VERSION],
-  [1.14.1])
+  [1.14.2])
 m4_define([AT_PACKAGE_STRING],
-  [libosmocore 1.14.1])
+  [libosmocore 1.14.2])
 m4_define([AT_PACKAGE_BUGREPORT],
   [[email protected]])
 m4_define([AT_PACKAGE_URL],
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/tests/sms/sms_test.c 
new/libosmocore-1.14.2/tests/sms/sms_test.c
--- old/libosmocore-1.14.1/tests/sms/sms_test.c 2026-07-22 12:35:06.000000000 
+0200
+++ new/libosmocore-1.14.2/tests/sms/sms_test.c 2026-08-21 07:20:41.000000000 
+0200
@@ -380,7 +380,8 @@
        memcpy(tmp, septet_data, concatenated_part1_septet_length);
 
        /* In our case: test_multiple_decode[0].ud_hdr_ind equals number of 
padding bits*/
-       octet_length = gsm_septet_pack(coded, tmp, 
concatenated_part1_septet_length, test_multiple_encode[0].ud_hdr_ind);
+       octet_length = gsm_septet_pack2(coded, sizeof(coded), tmp, 
concatenated_part1_septet_length, test_multiple_encode[0].ud_hdr_ind);
+       OSMO_ASSERT(octet_length == 134);
 
        /* copy header */
        memset(tmp, 0x42, sizeof(tmp));
@@ -398,7 +399,8 @@
        memcpy(tmp, septet_data + concatenated_part1_septet_length, 
concatenated_part2_septet_length);
 
        /* In our case: test_multiple_decode[1].ud_hdr_ind equals number of 
padding bits*/
-       octet_length = gsm_septet_pack(coded, tmp, 
concatenated_part2_septet_length, test_multiple_encode[1].ud_hdr_ind);
+       octet_length = gsm_septet_pack2(coded, sizeof(coded), tmp, 
concatenated_part2_septet_length, test_multiple_encode[1].ud_hdr_ind);
+       OSMO_ASSERT(octet_length == 36);
 
        /* copy header */
        memset(tmp, 0x42, sizeof(tmp));
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/tests/testsuite 
new/libosmocore-1.14.2/tests/testsuite
--- old/libosmocore-1.14.1/tests/testsuite      2026-07-22 12:35:26.000000000 
+0200
+++ new/libosmocore-1.14.2/tests/testsuite      2026-08-21 07:21:04.000000000 
+0200
@@ -1012,7 +1012,7 @@
 # List of tests.
 if $at_list_p; then
   cat <<_ATEOF || at_write_fail=1
-libosmocore 1.14.1 test suite test groups:
+libosmocore 1.14.2 test suite test groups:
 
  NUM: FILE-NAME:LINE     TEST-GROUP-NAME
       KEYWORDS
@@ -1053,7 +1053,7 @@
   exit $at_write_fail
 fi
 if $at_version_p; then
-  printf "%s\n" "$as_me (libosmocore 1.14.1)" &&
+  printf "%s\n" "$as_me (libosmocore 1.14.2)" &&
   cat <<\_ATEOF || at_write_fail=1
 
 Copyright (C) 2021 Free Software Foundation, Inc.
@@ -1241,11 +1241,11 @@
 
 # Banners and logs.
 printf "%s\n" "## ------------------------------ ##
-## libosmocore 1.14.1 test suite. ##
+## libosmocore 1.14.2 test suite. ##
 ## ------------------------------ ##"
 {
   printf "%s\n" "## ------------------------------ ##
-## libosmocore 1.14.1 test suite. ##
+## libosmocore 1.14.2 test suite. ##
 ## ------------------------------ ##"
   echo
 
@@ -2062,7 +2062,7 @@
   printf "%s\n" "Please send $at_msg and all information you think might help:
 
    To: <[email protected]>
-   Subject: [libosmocore 1.14.1] $as_me: $at_msg1$at_msg2
+   Subject: [libosmocore 1.14.2] $as_me: $at_msg1$at_msg2
 
 You may investigate any problem if you feel able to do so, in which
 case the test suite provides a good starting point.  Its output may
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/tests/ussd/ussd_test.c 
new/libosmocore-1.14.2/tests/ussd/ussd_test.c
--- old/libosmocore-1.14.1/tests/ussd/ussd_test.c       2026-07-22 
12:35:06.000000000 +0200
+++ new/libosmocore-1.14.2/tests/ussd/ussd_test.c       2026-08-21 
07:20:41.000000000 +0200
@@ -41,6 +41,16 @@
        0x05, 0x02, 0x01, 0x24
 };
 
+/* Same REGISTER/ProcessUssReq message as ussd_request[], except the
+ * USSD-String octet count (index 18) claims 100 bytes while the message
+ * only ever carries 6.  Must be rejected, not read past the buffer end. */
+static const uint8_t ussd_process_uss_req_overflow[] = {
+       0x0b, 0x7b, 0x1c, 0x15, 0xa1, 0x13, 0x02, 0x01,
+       0x03, 0x02, 0x01, 0x3b, 0x30, 0x0b, 0x04, 0x01,
+       0x0f, 0x04, 0x64, 0x2a, 0xd5, 0x4c, 0x16, 0x1b,
+       0x01, 0x7f, 0x01, 0x00
+};
+
 static const uint8_t interrogate_ss[] = {
        0x0b, 0x7b, 0x1c, 0x0d, 0xa1, 0x0b, 0x02, 0x01,
        0x03, 0x02, 0x01, 0x0e, 0x30, 0x03, 0x04, 0x01,
@@ -221,6 +231,23 @@
        printf("\n");
 }
 
+/* parse_process_uss_req() must reject a USSD-String octet count that
+ * exceeds the bytes actually remaining in the message, rather than only
+ * capping it against GSM0480_USSD_OCTET_STRING_LEN and reading past the
+ * end of the buffer. */
+static void test_process_uss_req_overflow(void)
+{
+       int rc;
+
+       printf("[i] Testing parse_process_uss_req() against an oversized "
+              "USSD-String length\n");
+
+       rc = parse_ussd(ussd_process_uss_req_overflow, 
sizeof(ussd_process_uss_req_overflow));
+       OSMO_ASSERT(rc == 0);
+
+       printf("\n");
+}
+
 int main(int argc, char **argv)
 {
        struct ss_request req;
@@ -237,6 +264,9 @@
        /* Test gsm0480_parse_facility_ie() */
        test_parse_facility_ie();
 
+       /* Test parse_process_uss_req() against an oversized length byte */
+       test_process_uss_req_overflow();
+
        memset(&req, 0, sizeof(req));
        gsm0480_decode_ss_request((struct gsm48_hdr *) ussd_request,
                sizeof(ussd_request), &req);
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libosmocore-1.14.1/tests/ussd/ussd_test.ok 
new/libosmocore-1.14.2/tests/ussd/ussd_test.ok
--- old/libosmocore-1.14.1/tests/ussd/ussd_test.ok      2026-07-22 
12:35:06.000000000 +0200
+++ new/libosmocore-1.14.2/tests/ussd/ussd_test.ok      2026-08-21 
07:20:41.000000000 +0200
@@ -12,6 +12,8 @@
 [?] Data length: expected 0x01, decoded 0x01
 [?] Data: expected 32, decoded 32
 
+[i] Testing parse_process_uss_req() against an oversized USSD-String length
+
 Tested if it still works. Text was: **321#
 interrogateSS CFU text..'' code 33
 Testing parsing a USSD request and truncated versions

Reply via email to