CVE-2026-56789

MEDIUM

RTKLIB 2.4.3 - Heap Buffer Overflow and Stack Read via Oversized RINEX Epoch Satellite Count

Title source: cna
STIX 2.1

Description

RTKLIB through 2.4.3 contains a heap buffer overflow vulnerability in the readrnxobsb function in src/rinex.c that allows attackers to trigger memory corruption by failing to clamp satellite count values from RINEX epoch headers. Attackers can craft malicious RINEX files declaring more than 64 satellites per epoch to cause heap buffer overflow writes and out-of-bounds stack reads, crashing RTKLIB-based applications including rnx2rtkp and RTKPOST.

References (2)

Core 2
Core References
Exploit technical-description exploit
Researcher Disclosure
https://github.com/tomojitakasu/RTKLIB/issues/796

Scores

CVSS v3 6.5
EPSS 0.0025
EPSS Percentile 16.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-122
Status published
Products (2)
rtklib/rtklib < 2.4.3
tomojitakasu/RTKLIB < 2.4.3
Published Jun 25, 2026
Tracked Since Jun 26, 2026