Executive brief
A vulnerability exists in the core libraries of RTI Connext Micro, a communication framework used in embedded and real-time systems. An attacker could exploit this flaw to crash the system or gain unauthorized access to sensitive data stored in memory. This could lead to significant service disruptions or the exposure of confidential operational information.
Technical details
An integer underflow (CWE-191) exists in the Core Libraries of RTI Connext Micro versions 4.0.0 through 4.2.x. The flaw occurs during memory management or packet processing, where a wrap-around error allows an attacker to trigger a buffer overread. This can be exploited remotely over the network without authentication or user interaction. Successful exploitation can result in the disclosure of sensitive information from the process memory or a denial-of-service condition. The issue is addressed in version 4.3.0.
Affected products
- RTI Connext Micro (Core Libraries) 4.0.0 before 4.3.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory