RTKLIB through 2.4.3 contains an out-of-bounds read vulnerability in getcodepri function when processing unrecognized RINEX observation codes, allowing attackers to trigger denial of service. Crafted RINEX files with unknown observation types cause negative array indexing into the codepris table, resulting in reliable crashes and potential memory disclosure of adjacent global data.
References
| Link | Resource |
|---|---|
| https://github.com/tomojitakasu/RTKLIB/issues/797 | Exploit Issue Tracking Third Party Advisory |
| https://www.vulncheck.com/advisories/rtklib-out-of-bounds-read-via-negative-array-index-in-getcodepri | Third Party Advisory |
| https://github.com/tomojitakasu/RTKLIB/issues/797 | Exploit Issue Tracking Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-06-25 19:16
Updated : 2026-07-14 22:17
NVD link : CVE-2026-56788
Mitre link : CVE-2026-56788
CVE.ORG link : CVE-2026-56788
JSON object : View
Products Affected
rtklib
- rtklib
CWE
CWE-125
Out-of-bounds Read
