Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73146

Опубликовано: 13 июл. 2026
Источник: redhat

Описание

A flaw was found in svxlink's svxreflector component. A reentrant client deletion triggered via a sendError() write-failure path leads to a use-after-free on the client object. A remote attacker can trigger this condition to crash the reflector server or potentially achieve arbitrary code execution.

Отчет

svxlink is not shipped in any Red Hat Enterprise product. It is available in Fedora as a community-maintained package.

Меры по смягчению последствий

Update svxlink to version 26.05.1 or later.

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2513801svxlink: svxlink: Use-after-free via reentrant client deletion in svxreflector

Связанные уязвимости

ubuntu
16 дней назад

[GHSA-r2gm-p682-3mpm: svxreflector: use-after-free via reentrant client deletion]

debian

[GHSA-r2gm-p682-3mpm: svxreflector: use-after-free via reentrant client deletion]