oss-sec mailing list archives

[security] critical vulnerabilities patched in svxlink (RCE)


From: Mark Rose <markrose () markrose ca>
Date: Sun, 26 Jul 2026 10:31:43 -0600

Hello,

A new version of svxlink has been released that fixes many
vulnerabilities. The worst has a CVSS/3.1 score of 9.8.

https://github.com/sm0svx/svxlink/security/advisories

The version containing the fixes is 26.05.1.

All prior versions from at least the past 13 years are vulnerable to
remote code execution. All maintained packages for older versions will
require backports.

Regards,
Mark Rose


Current thread: