VYPR
Medium severity4.4NVD Advisory· Published Jun 25, 2026· Updated Jul 14, 2026

CVE-2026-56788

CVE-2026-56788

Description

RTKLIB through 2.4.3 contains an out-of-bounds read vulnerability in getcodepri function when processing unrecognized RINEX observation codes, allowing attackers to trigger denial of service. Crafted RINEX files with unknown observation types cause negative array indexing into the codepris table, resulting in reliable crashes and potential memory disclosure of adjacent global data.

Affected products

3
  • Range: <=2.4.3
  • RTKLIB/RTKLIB2 versions
    cpe:2.3:a:rtklib:rtklib:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:rtklib:rtklib:*:*:*:*:*:*:*:*range: <=2.4.3
    • (no CPE)range: <=2.4.3

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.