Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73151

Опубликовано: 13 июл. 2026
Источник: redhat

Описание

A flaw was found in svxlink's remotetrx NetUplink component. An unvalidated audio length field enables an out-of-bounds read, and when AUTH_KEY is not set, transceiver control functions are exposed to unauthenticated remote access. This allows unauthorized control of radio hardware connected to the svxlink system.

Отчет

svxlink is not shipped in any Red Hat Enterprise product. It is available in Fedora as a community-maintained package.

Меры по смягчению последствий

Update svxlink to version 26.05.1 or later.

Дополнительная информация

Статус:

Critical
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2513806svxlink: svxlink: Unvalidated audio length and exposed transceiver control in remotetrx

Связанные уязвимости

ubuntu
16 дней назад

[GHSA-x5r8-rq62-q9cj: remotetrx: unvalidated audio length + exposed transceiver control]

debian

[GHSA-x5r8-rq62-q9cj: remotetrx: unvalidated audio length + exposed transceiver control]