Executive brief
RTI Connext Professional is a connectivity framework used for real-time data exchange in critical industrial and defense systems. A vulnerability in its core libraries could allow an attacker to cause system crashes or potentially access sensitive information by sending specially crafted data. This could lead to service outages or operational disruptions in environments relying on this communication middleware.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Core Libraries of RTI Connext Professional. The flaw is triggered when the software processes malformed input that causes it to read beyond the end of the intended buffer. An unauthenticated attacker can exploit this over the network without user interaction. Successful exploitation can result in a denial-of-service (system crash) or the leakage of sensitive data from memory. The vulnerability affects multiple versions across the 5.x, 6.x, and 7.x release branches; users should update to the respective patched versions (e.g., 7.7.0 or 7.3.1.3) as specified in the advisory.
Affected products
- RTI Connext Professional (Core Libraries) 7.4.0 before 7.7.0, 7.0.0 before 7.3.1.3, 6.1.0 before 6.1.*, 6.0.0 before 6.0.*, 5.3.0 before 5.3.*, 5.0.0 before 5.2.*
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory