Executive brief
RTI Connext Professional is a middleware platform used to connect distributed systems and applications across networks. An out-of-bounds read vulnerability in its core libraries allows an attacker to read beyond allocated buffer boundaries, potentially exposing sensitive data or causing application instability. This affects multiple versions of the product across different release series.
Technical details
An out-of-bounds read vulnerability exists in the core libraries of RTI Connext Professional, enabling an attacker to overread buffer contents beyond their intended boundaries. The vulnerability affects multiple version ranges including 7.4.0–7.7.0.1, 7.0.0–7.3.1.6, and earlier 6.x and 5.x versions. Patched versions are available for active long-term support releases.
Affected products
- RTI Connext Professional 5.0.0–5.1.*, 5.2.0–5.2.*, 5.3.0–5.3.*, 6.0.0–6.0.*, 6.1.0–6.1.*, 7.0.0–7.3.1.6, 7.4.0–7.7.0.1
Timeline
- 2026-09-22: disclosed