CVE-2026-95622 is a reachable assertion vulnerability in ModemManager while parsing Cell Broadcast Messages. Certain 3GPP data-coding-scheme values, including 8-bit and reserved character sets, are not handled. A crafted Cell Broadcast PDU can cause the ModemManager process to hit an assertion and abort.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains README.md (1,870 bytes) and a standalone C harness, poc_cbm.c (2,941 bytes), with no exploit-framework integration. The README attributes the issue to CVE-2026-95622, but that identifier and the reported vulnerability have not been independently verified here. The harness constructs a fixed 88-byte Cell Broadcast PDU and directly calls ModemManager's internal mm_cbm_part_new_from_binary_pdu() parser. Its DCS byte, 0x44, selects 8-bit data; source comments explain that an unhandled encoding reaches an assertion instead of being rejected safely. Unlike the README's characterization as malformed input, the source describes this DCS as standards-valid. The code attempts an actual crash rather than merely checking a version, but it contains no wireless transmitter, network client, privilege escalation, persistence, or exfiltration functionality. Remote daemon impact is conditional on equivalent input reaching the parser through modem CBM or QMI ingestion. If the call returns, the harness prints the result and error, frees resources, and exits successfully; a normal return alone does not conclusively establish that the target is patched. No runtime network endpoints or file operations appear in the code. Build instructions and observed crash output are not supplied, despite a reference to missing repro.txt. The repository URL, analyzed Git reference, and archive size were not provided; empty strings and zero represent unavailable metadata.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical network-accessible vulnerability affecting Debian Linux 12.0, 13.0, and 14.0 according to the referenced assessment plugin. The listed CVSS v3 vector indicates unauthenticated remote exploitation with high impact to confidentiality, integrity, and availability.
A medium-severity denial-of-service vulnerability in ModemManager's Cell Broadcast Message parsing. Crafted Cell Broadcast PDUs using unhandled 3GPP data-coding-scheme values can trigger a reachable assertion, aborting ModemManager and potentially causing a persistent service failure after repeated crashes.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.