high · CVSS v3 7.8 · CVSS v4 8.6
CVE-2026-19477
A stack-based buffer overflow vulnerability exists in the MCC Universal Library for Linux (uldaq) in versions v1.2.1 and prior. This defect
Overview
A stack-based buffer overflow vulnerability exists in the MCC Universal Library for Linux (uldaq) in versions v1.2.1 and prior. This defect occurs within library processing functions and can be triggered by processing unvalidated input. If exploited, it may lead to information disclosure or arbitrary code execution on the host system.
Description
There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq). This may result in information disclosure or arbitrary code execution. This vulnerability affects MCC Universal Library for Linux (uldaq) v1.2.1 and prior versions.
Impact
The vulnerability impacts the confidentiality, integrity, and availability of systems running vulnerable versions of uldaq. Attackers able to interact with affected measurement and data acquisition applications could potentially execute arbitrary code or harvest sensitive memory contents. Organizations utilizing this library for industrial or laboratory automation are primarily at risk.
Remediation
Review internal software inventories to identify systems utilizing MCC Universal Library for Linux (uldaq) version v1.2.1 or earlier. Apply official vendor patches or updates as soon as they become available. Implement network segmentation and least-privilege access controls to limit potential exposure of data acquisition services.
Risk context
This vulnerability carries a CVSS v3 score of 7.8 (High) and a CVSS v4 score of 8.6, indicating significant severity if leveraged in targeted environments. Although EPSS data is currently unavailable, defenders should prioritize patching based on asset exposure and the potential for code execution.
Affected products
- MCC Universal Library for Linux (uldaq)
Scores
- Severity
- high
- CVSS v2
- 7.2
- CVSS v3
- 7.8
- CVSS v4
- 8.6
- EPSS
- —