Executive brief
A security vulnerability exists in the core libraries of RTI Connext Micro, a communication framework used in embedded and resource-constrained systems. An attacker could exploit this flaw to cause a system crash or service disruption by sending specially crafted data. This could lead to a loss of availability for critical real-time applications relying on this software for data distribution.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Core Libraries of RTI Connext Micro versions 4.0.0 through 4.2.x. The flaw is triggered when the software processes malformed input, leading to a buffer overread. An unauthenticated attacker can exploit this over the network without user interaction. According to the vendor's CVSS 4.0 assessment, the primary impact is high availability loss (VA:H), likely resulting in a crash of the affected process. The vulnerability is addressed in version 4.3.0.
Affected products
- RTI Connext Micro (Core Libraries) 4.0.0 before 4.3.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory