CVE-2025-41739: CODESYS Control - Linux/QNX SysSocket flaw
An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41739?
CVE-2025-41739 has a high severity rating due to the potential for unauthenticated remote exploitation and denial of service.
How do I fix CVE-2025-41739?
To fix CVE-2025-41739, ensure you update to the latest version of CODESYS Control that addresses this vulnerability.
What is the impact of CVE-2025-41739 if exploited?
Exploiting CVE-2025-41739 can lead to an out-of-bounds read, resulting in a denial of service for the affected CODESYS Control runtime systems.
Who is affected by CVE-2025-41739?
CVE-2025-41739 affects users of the CODESYS Control runtime system on Linux and QNX platforms.
Is CVE-2025-41739 an authenticated or unauthenticated vulnerability?
CVE-2025-41739 is an unauthenticated vulnerability, allowing remote attackers to exploit it without credentials.