Executive brief
MCC Universal Library for Linux (uldaq) is a data acquisition software library used by engineers and developers to interface with measurement hardware on Linux systems. A stack-based buffer overflow vulnerability allows an attacker with local access to execute arbitrary code or disclose sensitive information, potentially compromising system integrity and the confidentiality of measurement data.
Technical details
This is a classic stack-based buffer overflow vulnerability (CWE-121) in the MCC Universal Library for Linux (uldaq) affecting versions 1.2.1 and earlier. The vulnerability requires local access to the affected system, does not require authentication or elevated privileges, but does require user interaction to trigger. An attacker can overflow a stack buffer to achieve arbitrary code execution or information disclosure. The issue has been patched in version 1.2.2 and later, which should be applied immediately.
Affected products
- National Instruments MCC Universal Library for Linux 1.2.1 and prior
Timeline
- 2026-09-17: disclosed
- 2026-09-24: patched: Version 1.2.2 available