Medium severity6.5NVD Advisory· Published Jun 25, 2026· Updated Jul 14, 2026
CVE-2026-56789
CVE-2026-56789
Description
RTKLIB through 2.4.3 contains a heap buffer overflow vulnerability in the readrnxobsb function in src/rinex.c that allows attackers to trigger memory corruption by failing to clamp satellite count values from RINEX epoch headers. Attackers can craft malicious RINEX files declaring more than 64 satellites per epoch to cause heap buffer overflow writes and out-of-bounds stack reads, crashing RTKLIB-based applications including rnx2rtkp and RTKPOST.
Affected products
3- Range: <=2.4.3
Patches
Vulnerability mechanics
References
2- github.com/tomojitakasu/RTKLIB/issues/796nvdExploitIssue TrackingThird Party Advisory
- www.vulncheck.com/advisories/rtklib-heap-buffer-overflow-and-stack-read-via-oversized-rinex-epoch-satellite-countnvdThird Party Advisory
News mentions
0No linked articles in our index yet.