Executive brief
RTI Connext Professional is a data distribution middleware used to connect applications and devices in real-time systems. A double free vulnerability in its core libraries could allow an attacker to manipulate files or cause unexpected behavior, potentially compromising the integrity of systems relying on Connext for inter-process communication.
Technical details
A double free vulnerability exists in the core libraries of RTI Connext Professional that enables file manipulation. The vulnerability affects versions 7.4.0 through 7.7.0.0 and 7.1.0 through 7.3.1.5, with patches available in 7.7.0.1 and 7.3.1.6 respectively. Exploitation requires the ability to trigger the vulnerable code path in the core libraries.
Affected products
- RTI Connext Professional 7.4.0 to 7.7.0.0, 7.1.0 to 7.3.1.5
Timeline
- 2026-09-22: disclosed