CVE-2026-56788

MEDIUM

RTKLIB 2.4.3 - Out-of-bounds Read via Negative Array Index in getcodepri

Title source: cna
STIX 2.1

Description

RTKLIB through 2.4.3 contains an out-of-bounds read vulnerability in getcodepri function when processing unrecognized RINEX observation codes, allowing attackers to trigger denial of service. Crafted RINEX files with unknown observation types cause negative array indexing into the codepris table, resulting in reliable crashes and potential memory disclosure of adjacent global data.

References (2)

Core 2
Core References
Exploit technical-description exploit
Researcher Disclosure
https://github.com/tomojitakasu/RTKLIB/issues/797

Scores

CVSS v3 4.4
EPSS 0.0014
EPSS Percentile 4.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (2)
rtklib/rtklib < 2.4.3
tomojitakasu/RTKLIB < 2.4.3
Published Jun 25, 2026
Tracked Since Jun 26, 2026