CVE-2026-73143
Description
A flaw was found in svxlink's RtlTcp component. A malformed rtl_tcp greeting from a remote source triggers an unconditional exit(1) call, causing the entire svxlink daemon to terminate. A remote attacker can exploit this to achieve a complete denial of service of the repeater controller.
Statement
svxlink is not shipped in any Red Hat Enterprise product. It is available in Fedora as a community-maintained package.
Mitigation
Update svxlink to version 26.05.1 or later.
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Crash, Exit, or Restart
An attacker that can trigger an assert statement can still lead to a denial of service if the relevant code can be triggered by an attacker, and if the scope of the assert() extends beyond the attacker's own session.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.