svxlink: svxlink: Remote code execution via TCL command injection in reflector client
Published Jul 15, 2026
No CVSS score
Description
A flaw was found in svxlink's reflector client. The talker_start and talker_stop event handlers directly concatenate a server-supplied talker callsign into Tcl_Eval commands without any sanitization or escaping. A malicious or compromised reflector server can supply a crafted callsign containing TCL metacharacters to achieve arbitrary OS command execution with the privileges of the svxlink process.
Affected products
No data.
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
svxlink is not shipped in any Red Hat Enterprise product. It is available in Fedora as a community-maintained package.
Red Hat mitigation
Update svxlink to version 26.05.1 or later.
References (5)
- https://access.redhat.com/security/cve/CVE-2026-73147 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2513802 Issue Tracking
- https://github.com/sm0svx/svxlink/security/advisories/GHSA-pc2g-2p95-4cr5
- https://nvd.nist.gov/vuln/detail/CVE-2026-73147
- https://www.cve.org/CVERecord?id=CVE-2026-73147
Change history (0)
No recorded changes yet.