{"id":"CVE-2026-71979","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-71979","summary":"INDI (Instrument Neutral Distributed Interface) indiserver through 2.2.4.2, fixed in commit 96bbd7f, contains a stack buffer overflow vulnerability that allows unauthenticated remote…","details":"INDI (Instrument Neutral Distributed Interface) indiserver through 2.2.4.2, fixed in commit 96bbd7f, contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to crash the daemon by sending malformed XML with mismatched tags whose names exceed 1024 bytes. Attackers can send a single TCP packet on port 7624 with mismatched XML tags to trigger an unbounded sprintf() write into a fixed 1024-byte stack buffer in MsgQueue.cpp, terminating the daemon and disrupting all active client and driver sessions.","published":"2026-08-17T17:40:38.095Z","modified":"2026-08-17T17:40:38.095Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/indilib/indi/commit/96bbd7f564bbb128a129019e44eadd40dd49cff9","label":"indilib/indi@96bbd7f"},"references":[{"type":"REPORT","url":"https://github.com/indilib/indi/issues/2472"},{"type":"FIX","url":"https://github.com/indilib/indi/commit/96bbd7f564bbb128a129019e44eadd40dd49cff9"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/indi-indiserver-stack-buffer-overflow-via-xml-tag-parsing"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-17T17:40:38.095Z"}}