Back

svxlink: svxlink: Remote code execution via TCL command injection in reflector client

Published Jul 15, 2026

Description

A flaw was found in svxlink's reflector client. The talker_start and talker_stop event handlers directly concatenate a server-supplied talker callsign into Tcl_Eval commands without any sanitization or escaping. A malicious or compromised reflector server can supply a crafted callsign containing TCL metacharacters to achieve arbitrary OS command execution with the privileges of the svxlink process.

Affected products

Remediation

Red Hat statement

svxlink is not shipped in any Red Hat Enterprise product. It is available in Fedora as a community-maintained package.

Red Hat mitigation

Update svxlink to version 26.05.1 or later.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status n/a
Assigner n/a
Published Jul 15, 2026
Updated n/a
Reserved n/a
NVD
Status n/a
Modified n/a
Red Hat
Severity Important
Public date Jul 15, 2026
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a