Back

svxlink: svxlink: Unvalidated audio length and exposed transceiver control in remotetrx

Published Jul 13, 2026

Description

A flaw was found in svxlink's remotetrx NetUplink component. An unvalidated audio length field enables an out-of-bounds read, and when AUTH_KEY is not set, transceiver control functions are exposed to unauthenticated remote access. This allows unauthorized control of radio hardware connected to the svxlink system.

Affected products

Remediation

Red Hat statement

svxlink is not shipped in any Red Hat Enterprise product. It is available in Fedora as a community-maintained package.

Red Hat mitigation

Update svxlink to version 26.05.1 or later.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status n/a
Assigner n/a
Published Jul 13, 2026
Updated n/a
Reserved n/a
NVD
Status n/a
Modified n/a
Red Hat
Severity Critical
Public date Jul 13, 2026