The GOOSE payload parser contains a boundary handling flaw that can be
triggered by a single unauthenticated Layer 2 multicast frame on the
process bus. When processing specific payload fields, an attacker
controlled inner element length may exceed its enclosing length, causing
the parser to over read by one byte. This out-of-bounds read reliably
terminates the subscriber process, resulting in a denial-of-service
condition.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-30 23:16
Updated : 2026-09-03 17:58
NVD link : CVE-2026-66364
Mitre link : CVE-2026-66364
CVE.ORG link : CVE-2026-66364
JSON object : View
Products Affected
No product.
CWE
CWE-125
Out-of-bounds Read
