CVE-2026-73152
Description
A flaw was found in svxlink's EchoLink proxy implementation. An integer truncation in message-length handling can result in incorrect buffer sizes, leading to potential memory corruption when processing specially crafted proxy messages.
Statement
svxlink is not shipped in any Red Hat Enterprise product. It is available in Fedora as a community-maintained package.
Mitigation
Update svxlink to version 26.05.1 or later.
Understanding the Weakness (CWE)
Other,Integrity
Technical Impact: Unexpected State; Quality Degradation
The program could wind up using the wrong number and generate incorrect results. If the number is used to allocate resources or make a security decision, then this could introduce a vulnerability.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.