CVE-2026-73143

Description

A flaw was found in svxlink's RtlTcp component. A malformed rtl_tcp greeting from a remote source triggers an unconditional exit(1) call, causing the entire svxlink daemon to terminate. A remote attacker can exploit this to achieve a complete denial of service of the repeater controller.

Statement

svxlink is not shipped in any Red Hat Enterprise product. It is available in Fedora as a community-maintained package.

Mitigation

Update svxlink to version 26.05.1 or later.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Crash, Exit, or Restart

An attacker that can trigger an assert statement can still lead to a denial of service if the relevant code can be triggered by an attacker, and if the scope of the assert() extends beyond the attacker's own session.

Frequently Asked Questions

Want to get errata notifications? Sign up here.