Home

Description

RTKLIB through 2.4.3 contains an out-of-bounds read vulnerability in getcodepri function when processing unrecognized RINEX observation codes, allowing attackers to trigger denial of service. Crafted RINEX files with unknown observation types cause negative array indexing into the codepris table, resulting in reliable crashes and potential memory disclosure of adjacent global data.

PUBLISHED Reserved 2026-06-23 | Published 2026-06-25 | Updated 2026-06-25 | Assigner VulnCheck




MEDIUM: 4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N

MEDIUM: 4.4CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

Problem types

Out-of-bounds Read

Product status

Default status
unaffected

Any version
affected

Credits

FuzzingLabs finder

References

github.com/tomojitakasu/RTKLIB/issues/797 (Researcher Disclosure) technical-description exploit

www.vulncheck.com/...-via-negative-array-index-in-getcodepri third-party-advisory

cve.org (CVE-2026-56788)

nvd.nist.gov (CVE-2026-56788)

Download JSON