Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73150

Опубликовано: 13 июл. 2026
Источник: redhat

Описание

A flaw was found in svxlink's LocationInfo/APRS functionality. The updateQsoStatus() function in AprsTcpClient.cpp formats a remote EchoLink station's callsign and info string into a fixed 80-byte stack buffer using sprintf without length checks. A remote attacker controlling an EchoLink station can supply a long callsign or info string to overflow the buffer, potentially enabling code execution.

Отчет

svxlink is not shipped in any Red Hat Enterprise product. It is available in Fedora as a community-maintained package.

Меры по смягчению последствий

Update svxlink to version 26.05.1 or later.

Дополнительная информация

Статус:

Important
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2513805svxlink: svxlink: Buffer overflow in APRS message construction

Связанные уязвимости

ubuntu
16 дней назад

[GHSA-4f8x-49pf-3x5v: Buffer overflow in APRS message construction]

debian

[GHSA-4f8x-49pf-3x5v: Buffer overflow in APRS message construction]