CVE-2026-73152

Description

A flaw was found in svxlink's EchoLink proxy implementation. An integer truncation in message-length handling can result in incorrect buffer sizes, leading to potential memory corruption when processing specially crafted proxy messages.

Statement

svxlink is not shipped in any Red Hat Enterprise product. It is available in Fedora as a community-maintained package.

Mitigation

Update svxlink to version 26.05.1 or later.

Understanding the Weakness (CWE)

Other,Integrity

Technical Impact: Unexpected State; Quality Degradation

The program could wind up using the wrong number and generate incorrect results. If the number is used to allocate resources or make a security decision, then this could introduce a vulnerability.

Frequently Asked Questions

Want to get errata notifications? Sign up here.