{"id":"CVE-2026-42996","details":"JS8Call through 2.3.1 and JS8Call-improved before 3.0 have a stack-based buffer overflow via a radio transmission of @APRSIS GRID followed by a long Maidenhead locator. This occurs in grid2deg in APRSISClient.cpp.","aliases":["GHSA-98hp-pjp7-w62x"],"modified":"2026-07-22T03:09:00.038141Z","published":"2026-05-01T06:42:58.858Z","database_specific":{"cna_assigner":"mitre","cwe_ids":["CWE-121"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42996.json","unresolved_ranges":[{"extracted_events":[{"fixed":"3.0"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://amateur-radio-resources.sourceforge.io/PDF/JS8APRS.pdf"},{"type":"WEB","url":"https://github.com/js8call/js8call/blob/fd721e8b67eed84cb3c09d018205ab9a53e1a8b1/APRSISClient.cpp#L89-L102"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42996.json"},{"type":"ADVISORY","url":"https://github.com/JS8Call-improved/JS8Call-improved/security/advisories/GHSA-98hp-pjp7-w62x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42996"},{"type":"FIX","url":"https://github.com/JS8Call-improved/JS8Call-improved/commit/a6c7a19b82bbd7c2c0c892576f84d7449e8c7088"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/js8call-improved/js8call-improved","events":[{"introduced":"0"},{"fixed":"fd721e8b67eed84cb3c09d018205ab9a53e1a8b1"},{"fixed":"a6c7a19b82bbd7c2c0c892576f84d7449e8c7088"}],"database_specific":{"extracted_events":[{"introduced":"JS8Call"},{"fixed":"2.3.1"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["lib/2.6","lib/2.5","2.4","v2.2.0"],"database_specific":{"vanir_signatures_modified":"2026-07-22T03:09:00Z","vanir_signatures":[{"id":"CVE-2026-42996-250f31b0","signature_type":"Function","signature_version":"v1","source":"https://github.com/js8call-improved/js8call-improved/commit/a6c7a19b82bbd7c2c0c892576f84d7449e8c7088","target":{"file":"JS8_Main/APRSISClient.cpp","function":"APRSISClient::grid2deg"},"deprecated":false,"digest":{"function_hash":"310362226120168573999317246591988258414","length":1085}},{"deprecated":false,"digest":{"line_hashes":["7704383707382585762460477450412960954","45573664063618283326767607752469245288","208545788373079494033583903244752096422","69805230127947473845792696962174410171","146283949885922591490952867623073401660","38629222466732001122922191557100741996","298688861202126477694900392063424875158","11502150389775127945672555941005320745","158319704011829504241306459693300239463","125852044605167572997560515222226829810","123295126120006517314484893525258049488"],"threshold":0.9},"id":"CVE-2026-42996-c48c8117","signature_type":"Line","signature_version":"v1","source":"https://github.com/js8call-improved/js8call-improved/commit/a6c7a19b82bbd7c2c0c892576f84d7449e8c7088","target":{"file":"JS8_Main/APRSISClient.cpp"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42996.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:Y/R:U/V:D/RE:M/U:Green"}]}