Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73141

Опубликовано: 15 июл. 2026
Источник: redhat

Описание

A flaw was found in svxlink's audio decoders. A variable-length array on the stack is sized using an attacker-controlled encoded-frame length field received over the network. By sending a frame with an excessively large length value, a remote attacker can exhaust the stack, resulting in a denial of service.

Отчет

svxlink is not shipped in any Red Hat Enterprise product. It is available in Fedora as a community-maintained package.

Меры по смягчению последствий

Update svxlink to version 26.05.1 or later.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2513796svxlink: svxlink: Stack exhaustion via attacker-sized VLA in audio decoders

Связанные уязвимости

ubuntu
16 дней назад

[GHSA-xmcv-mjpv-x46q: Audio decoders: stack VLA exhaustion]

debian

[GHSA-xmcv-mjpv-x46q: Audio decoders: stack VLA exhaustion]