Hi!
I've just committed a patch that will cause libosmocore to abort in case we try to msgb_put() beyond the end fo the buffer or msgb_push() ahead of the start.
I hope we can uncover any hidden buffer under/overflows this way, if they exist.
Regards, Harald