PT-2026-52552 · Rtklib · Rtklib
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
RTKLIB versions prior to 2.4.4
Description
A heap buffer overflow occurs in the
readrnxobsb() function within src/rinex.c due to a failure to clamp satellite count values from RINEX epoch headers. An attacker can provide a malicious RINEX file specifying more than 64 satellites per epoch, leading to heap buffer overflow writes and out-of-bounds stack reads. This results in memory corruption and crashes in RTKLIB-based applications, such as rnx2rtkp and RTKPOST.Recommendations
Update RTKLIB to version 2.4.4 or later.
Exploit
Fix
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rtklib