A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize results in integer underflow. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Sun, 30 Aug 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize results in integer underflow. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | NASA cFS cFE Software Bus cfe_sb_util.c CFE_SB_GetUserDataLength integer underflow | |
| First Time appeared |
Nasa
Nasa cfs |
|
| Weaknesses | CWE-189 CWE-191 |
|
| CPEs | cpe:2.3:a:nasa:cfs:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nasa
Nasa cfs |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-30T05:30:09.275Z
Reserved: 2026-08-29T14:40:28.151Z
Link: CVE-2026-82480
No data.
Status : Received
Published: 2026-08-30T06:16:56.730
Modified: 2026-08-30T06:16:56.730
Link: CVE-2026-82480
No data.
OpenCVE Enrichment
Updated: 2026-08-30T06:30:07Z