CVE-2026-32863: Out-of-Bounds Read in sentry_transaction_context_set_operation()
There is a memory corruption vulnerability due to an out-of-bounds read in sentrytransactioncontextsetoperation() in NI LabVIEW. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32863?
CVE-2026-32863 is considered a critical vulnerability due to its potential for information disclosure and arbitrary code execution.
How do I fix CVE-2026-32863?
To fix CVE-2026-32863, users should update their NI LabVIEW software to the latest version provided by National Instruments.
Which versions of NI LabVIEW are affected by CVE-2026-32863?
CVE-2026-32863 affects NI LabVIEW versions up to 26.1.0 and several specific versions and patches released in 2023 and 2024.
What are the potential impacts of CVE-2026-32863?
The potential impacts of CVE-2026-32863 include memory corruption leading to crash, information leakage, or arbitrary code execution.
What is the nature of the vulnerability CVE-2026-32863?
CVE-2026-32863 is an out-of-bounds read vulnerability in the sentry_transaction_context_set_operation() function.