[CVE-2026-82480] A security flaw has been discovered in NASA cFS up to 7.0.1.

CVE-2026-82480 | CVSS: 7.4 | 严重级别: HIGH

A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize results in integer underflow. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.

参考链接:
https://vuldb.com/cve/CVE-2026-82480
https://vuldb.com/submit/888018
https://vuldb.com/vuln/397030

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部