CVE-2026-2467: Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.
Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1., from 6.0.0 before 6.0., from 5.3.0 before 5.3., from 5.0.0 before 5.2..
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
RTI Connext Professional (Core Libraries)to a version that resolves this vulnerability.Fixed in 7.7.0 - Upgrade
Upgrade
RTI Connext Professional (Core Libraries)to a version that resolves this vulnerability.Fixed in 7.3.1.3 - Upgrade
Upgrade
RTI Connext Professional (Core Libraries)to a version that resolves this vulnerability.Fixed in 6.1.* - Upgrade
Upgrade
RTI Connext Professional (Core Libraries)to a version that resolves this vulnerability.Fixed in 6.0.* - Upgrade
Upgrade
RTI Connext Professional (Core Libraries)to a version that resolves this vulnerability.Fixed in 5.3.* - Upgrade
Upgrade
RTI Connext Professional (Core Libraries)to a version that resolves this vulnerability.Fixed in 5.2.*
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2467?
CVE-2026-2467 has a risk rating of 60, indicating a moderate level of severity.
How do I fix CVE-2026-2467?
To fix CVE-2026-2467, upgrade RTI Connext Professional to the latest version above 7.7.0 or the corresponding secure versions for earlier releases.
What types of vulnerabilities does CVE-2026-2467 exploit?
CVE-2026-2467 exploits heap-based buffer overflow vulnerabilities, allowing potential overflow of variables and tags.
Which versions of RTI Connext Professional are affected by CVE-2026-2467?
CVE-2026-2467 affects RTI Connext Professional versions from 5.0.0 before 5.3.*, up to versions before 7.7.0.
What are the potential consequences of CVE-2026-2467?
The potential consequences of CVE-2026-2467 include application crashes, data corruption, and remote code execution due to buffer overflow.