Junglewise Threat Intelligence

CVE-2026-19477: MCC Universal Library for Linux stack-based buffer overflow

CVE-2026-19477 · Severity: high · CVSS 7.8 · Published 2026-09-17

Executive brief

MCC Universal Library for Linux (uldaq) is a data acquisition software library used by engineers and developers to interface with measurement hardware on Linux systems. A stack-based buffer overflow vulnerability allows an attacker with local access to execute arbitrary code or disclose sensitive information, potentially compromising system integrity and the confidentiality of measurement data.

Technical details

This is a classic stack-based buffer overflow vulnerability (CWE-121) in the MCC Universal Library for Linux (uldaq) affecting versions 1.2.1 and earlier. The vulnerability requires local access to the affected system, does not require authentication or elevated privileges, but does require user interaction to trigger. An attacker can overflow a stack buffer to achieve arbitrary code execution or information disclosure. The issue has been patched in version 1.2.2 and later, which should be applied immediately.

Affected products

  • National Instruments MCC Universal Library for Linux 1.2.1 and prior

Timeline

  • 2026-09-17: disclosed
  • 2026-09-24: patched: Version 1.2.2 available

References