Executive brief
INDI indiserver is a daemon that coordinates telescope control and astronomical instrumentation over TCP port 7624 with no authentication. An unauthenticated attacker can send a single malformed XML packet with mismatched tags to crash the daemon, disrupting all connected clients and drivers and preventing further observations or telescope operations.
Technical details
The vulnerability is a stack buffer overflow in lilxml.cpp:1281 within the oneXMLchar() function. The XML parser uses unbounded growString() to accumulate tag names from client input, then formats error messages via sprintf() into a fixed 1024-byte stack buffer (char err[1024] in MsgQueue.cpp:525) without length checking. An unauthenticated attacker on the network can send a single TCP packet on port 7624 containing mismatched XML tags with names exceeding 1024 bytes total (e.g., <AAAA...>x</BBBB...>), causing sprintf() to write far past the buffer boundary and crash the daemon. The fix bounds sprintf() calls with snprintf(ynot, XML_ERROR_SIZE, ...) and caps tag accumulation to prevent unbounded memory allocation.
Affected products
- INDI indiserver through 2.2.4.2
Timeline
- 2026-08-17: disclosed: CVE-2026-71979 published
- 2026-08-14: patched: Fix committed as 96bbd7f