PT-2026-52552 · Rtklib · Rtklib

·

CVE-2026-56789

·

Published

2026-06-25

·

Updated

2026-06-25

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions RTKLIB versions prior to 2.4.4
Description A heap buffer overflow occurs in the readrnxobsb() function within src/rinex.c due to a failure to clamp satellite count values from RINEX epoch headers. An attacker can provide a malicious RINEX file specifying more than 64 satellites per epoch, leading to heap buffer overflow writes and out-of-bounds stack reads. This results in memory corruption and crashes in RTKLIB-based applications, such as rnx2rtkp and RTKPOST.
Recommendations Update RTKLIB to version 2.4.4 or later.

Exploit

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56789

Affected Products

Rtklib