Executive brief
RTI Connext Professional is a middleware platform for distributed real-time systems communication. This vulnerability allows an attacker to read beyond allocated buffer boundaries in the core libraries, potentially exposing sensitive data or causing system instability. The issue affects multiple versions and requires network access to trigger.
Technical details
An out-of-bounds read combined with type confusion and incorrect function call arguments exists in RTI Connext Professional's core libraries. The vulnerability allows an attacker with network access to overread buffers, potentially disclosing sensitive information. Patches are available for affected versions 7.4.0–7.7.0.1 and 7.3.0–7.3.1.6.
Affected products
- RTI Connext Professional 7.3.0 before 7.3.1.6, 7.4.0 before 7.7.0.1
Timeline
- 2026-09-22: disclosed