Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 30 Aug 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize results in integer underflow. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | NASA cFS cFE Software Bus cfe_sb_util.c CFE_SB_GetUserDataLength integer underflow | |
| First Time appeared |
Nasa
Nasa cfs |
|
| Weaknesses | CWE-189 CWE-191 |
|
| CPEs | cpe:2.3:a:nasa:cfs:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nasa
Nasa cfs |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-31T17:06:07.604Z
Reserved: 2026-08-29T14:40:28.151Z
Link: CVE-2026-82480
Updated: 2026-08-31T17:06:02.791Z
Status : Received
Published: 2026-08-30T06:16:56.730
Modified: 2026-08-31T18:17:22.010
Link: CVE-2026-82480
No data.
OpenCVE Enrichment
Updated: 2026-08-30T07:00:05Z