Bug 2538940 (CVE-2026-54634)

Summary: CVE-2026-54634 Hamlib: Hamlib: Remote Unauthenticated Memory Corruption and Information Disclosure via `send_raw` command
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Hamlib, a library for controlling ham radio equipment. A remote, unauthenticated attacker could exploit a vulnerability in the `rigctld send_raw` command. This flaw involves writing data beyond the intended memory boundary (stack out-of-bounds write), which could cause the daemon to crash or corrupt memory, potentially leading to a denial of service or arbitrary code execution. Additionally, the vulnerability could lead to the disclosure of uninitialized memory, exposing sensitive information.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2539332, 2539333, 2539334    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-22 21:45:42 UTC
Hamlib is a ham radio control library for radios, rotators, and amplifiers. Prior to 4.7.2, the unauthenticated rigctld send_raw command on TCP port 4532 reaches rigctl_send_raw() in tests/rigctl_parse.c, which writes a NUL byte at buf[buf_len + 1] outside its 200-byte stack buffer, and rig_send_raw() in src/rig.c, which copies reply_len - 1 bytes instead of the actual nbytes received. A remote client can send the CR terminator with a short payload to trigger both flaws in one command under the default no-password configuration. The out-of-bounds write can crash the daemon or corrupt adjacent stack memory, while the oversized copy can return up to 198 bytes of uninitialized stack data to the client. This issue is fixed in version 4.7.2.