PT-2026-52550 · Rtklib · Rtklib
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
RTKLIB versions prior to 2.4.3
Description
An off-by-one out-of-bounds read exists in the
decode ssr3() function within the src/rtcm3.c file. This issue occurs when processing crafted RTCM3 SSR messages containing attacker-controlled signal mode fields, which can trigger a global buffer overflow. Remote attackers can exploit this by sending malicious SSR correction streams via NTRIP or serial connections, potentially leading to a denial of service or causing RTKLIB rovers and CORS servers to crash.Recommendations
Update RTKLIB to a version newer than 2.4.3.
As a temporary mitigation, restrict the processing of SSR correction streams from untrusted sources.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rtklib