CVE-2026-85445

MOOS-IvP through 24.8.1 contains a denial of service vulnerability in the Demuxer::addMuxPacket() function that trusts the packet count declared in mux headers without validation. Attackers can declare arbitrarily large packet counts to trigger unbounded memory allocation, exhausting system resources and causing service unavailability.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 23:17

Updated : 2026-09-08 20:07


NVD link : CVE-2026-85445

Mitre link : CVE-2026-85445

CVE.ORG link : CVE-2026-85445


JSON object : View

Products Affected

No product.

CWE
CWE-789

Memory Allocation with Excessive Size Value