Описание
A flaw was found in svxlink. A stack overflow in the StationData::setData function can be triggered by specially crafted input data, potentially allowing a remote attacker to crash the application or achieve arbitrary code execution.
Отчет
svxlink is not shipped in any Red Hat Enterprise product. It is available in Fedora as a community-maintained package.
Меры по смягчению последствий
Update svxlink to version 26.05.1 or later.
Дополнительная информация
Статус:
Critical
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2513809svxlink: svxlink: Stack overflow in StationData::setData