Critical severityNVD Advisory· Published May 1, 2026· Updated May 1, 2026
CVE-2026-42996
CVE-2026-42996
Description
JS8Call through 2.3.1 and JS8Call-improved before 3.0 have a stack-based buffer overflow via a radio transmission of @APRSIS GRID followed by a long Maidenhead locator. This occurs in grid2deg in APRSISClient.cpp.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- amateur-radio-resources.sourceforge.io/PDF/JS8APRS.pdfnvd
- github.com/JS8Call-improved/JS8Call-improved/commit/a6c7a19b82bbd7c2c0c892576f84d7449e8c7088nvd
- github.com/JS8Call-improved/JS8Call-improved/security/advisories/GHSA-98hp-pjp7-w62xnvd
- github.com/js8call/js8call/blob/fd721e8b67eed84cb3c09d018205ab9a53e1a8b1/APRSISClient.cppnvd
News mentions
0No linked articles in our index yet.