Описание
A flaw was found in svxlink's NetRx component. An unvalidated MsgAudio length field allows a remote attacker to trigger an out-of-bounds read beyond buffer boundaries, potentially leading to information disclosure or a crash.
Отчет
svxlink is not shipped in any Red Hat Enterprise product. It is available in Fedora as a community-maintained package.
Меры по смягчению последствий
Update svxlink to version 26.05.1 or later.
Дополнительная информация
Статус:
Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2513804svxlink: svxlink: Out-of-bounds read via unvalidated MsgAudio length in NetRx
Связанные уязвимости
ubuntu
16 дней назад
[GHSA-mh75-5pr3-qv2p: NetRx: out-of-bounds read via unvalidated MsgAudio length]
debian
[GHSA-mh75-5pr3-qv2p: NetRx: out-of-bounds read via unvalidated MsgAudio length]