CVE-2026-82480

A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize results in integer underflow. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-30 06:16

Updated : 2026-09-01 20:48


NVD link : CVE-2026-82480

Mitre link : CVE-2026-82480

CVE.ORG link : CVE-2026-82480


JSON object : View

Products Affected

No product.

CWE
CWE-189

Numeric Errors

CWE-191

Integer Underflow (Wrap or Wraparound)