Executive brief
RTI Connext Professional is middleware that enables real-time distributed communication for industrial and embedded systems. An integer overflow vulnerability in the Core Libraries allows attackers with local or network access to manipulate shared resources, potentially compromising system integrity or availability. The vulnerability affects multiple versions and requires a patch to remediate.
Technical details
An integer overflow or wraparound flaw combined with improper access control in RTI Connext Professional's Core Libraries permits shared resource manipulation. The vulnerability is reachable over the network or via local access and does not require authentication. Patches are available for affected versions: 7.7.0.1+ (7.4.x branch), 7.3.1.6+ (7.0.x branch), and 6.1.x fixed versions.
Affected products
- RTI Connext Professional 7.4.0 before 7.7.0.1, 7.0.0 before 7.3.1.6, 6.1.0 before 6.1.* (endpoint version unspecified)
Timeline
- 2026-09-22: disclosed