CVE-2026-82480 PUBLISHED

NASA cFS cFE Software Bus cfe_sb_util.c CFE_SB_GetUserDataLength integer underflow

Assigner: VulDB
Reserved: 29.08.2026 Published: 30.08.2026 Updated: 30.08.2026

A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize results in integer underflow. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X
CVSS Score: 5.3

Product Status

Vendor NASA
Product cFS
Versions
  • Version 7.0.0 is affected
  • Version 7.0.1 is affected

Credits

  • juntheworld (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Integer Underflow CWE
  • Numeric Error CWE