Executive brief
RTI Connext Professional is a data distribution middleware used to connect distributed systems and IoT applications. A heap-based buffer overflow in its Core Libraries could allow an attacker to crash the system, corrupt data, or potentially execute arbitrary code, compromising the integrity and availability of dependent applications.
Technical details
A heap-based buffer overflow vulnerability exists in RTI Connext Professional's Core Libraries component. The vulnerability can be triggered via network attack vectors and affects multiple version branches (5.2.3–5.2.*, 5.3.0–5.3.*, 6.0.0–6.0.*, 6.1.0–6.1.*, 7.0.0–7.3.1.6, and 7.4.0–7.7.0.1). Successful exploitation may result in memory corruption, denial of service, or remote code execution depending on attack context and memory layout.
Affected products
- RTI Connext Professional 5.2.3 before 5.2.*, 5.3.0 before 5.3.*, 6.0.0 before 6.0.*, 6.1.0 before 6.1.*, 7.0.0 before 7.3.1.6, 7.4.0 before 7.7.0.1
Timeline
- 2026-09-22: disclosed