Executive brief
RTI Connext Professional is a connectivity framework used for data exchange in distributed systems like industrial automation and aerospace. A memory management flaw in its core libraries could allow an attacker to disrupt system operations or cause a service outage. This could lead to a loss of availability for critical real-time communications and potentially impact system integrity.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in the Core Libraries of RTI Connext Professional. The flaw is triggered by improper handling of 'Overflow Variables and Tags' during data processing. An unauthenticated attacker can exploit this over the network without user interaction to cause a crash (denial of service) or potentially achieve limited unauthorized modification of data. The vulnerability affects multiple long-term support (LTS) versions, and RTI has released patches for active versions including 7.3.1.3 and 7.7.0.
Affected products
- RTI Connext Professional (Core Libraries) 7.4.0 before 7.7.0, 7.0.0 before 7.3.1.3, 6.1.0 before 6.1.*, 6.0.0 before 6.0.*, 5.3.0 before 5.3.*, 5.0.0 before 5.2.*
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory