Description
There is a memory corruption vulnerability due to an out-of-bounds read in sentry_transaction_context_set_operation() in NI LabVIEW. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.
Problem types
Product status
Any version before 23.0.0
23.1.0 (semver) before 23.3.9
24.1.0 (semver) before 24.3.6
25.1.0 (semver) before 25.3.4
26.1.0 (semver) before 26.1.1
Credits
Michael Heinzl
References
www.ni.com/...-corruption-vulnerabilities-in-ni-labview.html