svxlink: svxlink: Unvalidated audio length and exposed transceiver control in remotetrx
Published Jul 13, 2026
No CVSS score
Description
A flaw was found in svxlink's remotetrx NetUplink component. An unvalidated audio length field enables an out-of-bounds read, and when AUTH_KEY is not set, transceiver control functions are exposed to unauthenticated remote access. This allows unauthorized control of radio hardware connected to the svxlink system.
Affected products
No data.
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
svxlink is not shipped in any Red Hat Enterprise product. It is available in Fedora as a community-maintained package.
Red Hat mitigation
Update svxlink to version 26.05.1 or later.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
No EPSS score for this CVE.
References (5)
- https://access.redhat.com/security/cve/CVE-2026-73151 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2513806 Issue Tracking
- https://github.com/sm0svx/svxlink/security/advisories/GHSA-x5r8-rq62-q9cj
- https://nvd.nist.gov/vuln/detail/CVE-2026-73151
- https://www.cve.org/CVERecord?id=CVE-2026-73151
Change history (0)
No recorded changes yet.