Published:2026/10/06  Last Updated:2026/10/06

JVN#13510969
MCC Universal Library for Linux (uldaq) vulnerabile to buffer overflow

Overview

Universal Library for Linux (uldaq) provided by Measurement Computing Corporation contains a stack-based buffer overflow vulnerability.

Products Affected

  • Universal Library for Linux (uldaq) versions v1.2.1 and prior

Description

Universal Library for Linux (uldaq) provided by Measurement Computing Corporation contains the following vulnerability:

  • Stack-based Buffer Overflow (CWE-121)
    • CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.6
    • CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Base Score 7.8
    • CVE-2026-19477

Impact

Information disclosure or arbitrary code execution.

Solution

Update the Software
Update the affected product to the latest version according to the information provided by the developer.

Vendor Status

Vendor Link
National Instruments Corporation Stack-based Buffer Overflow Vulnerability in Linux (uldaq)

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Tsurumi Junichi of Panasonic Holdings Corporation reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia JVNDB-2026-000142