MEDIUM
NASA cFS CCSDS Packet Header to_lab_passthru_encode.c CFE_MSG_GetSize heap-based overflow
Published Apr 3, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.61%
Description
A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component CCSDS Packet Header Handler. Performing a manipulation results in heap-based buffer overflow. The attacker must have access to the local network to execute the attack. The project was informed of the problem early through an issue report but has not responded yet.
Affected products
-
- Version 7.0StatusaffectedConstraints-
- Version
- ≤ 7.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-18807 Advisory
- https://github.com/nasa/cFS/ product
- https://github.com/nasa/cFS/issues/952 issue-trackingIssue Tracking
- https://vuldb.com/submit/781950 third-party-advisoryThird Party AdvisoryVDB Entry
- https://vuldb.com/vuln/355078 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/vuln/355078/cti signaturepermissions-requiredPermissions RequiredVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-18807 | Advisory | |
| https://github.com/nasa/cFS/ | product | |
| https://github.com/nasa/cFS/issues/952 | issue-trackingIssue Tracking | |
| https://vuldb.com/submit/781950 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://vuldb.com/vuln/355078 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/vuln/355078/cti | signaturepermissions-requiredPermissions RequiredVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Apr 3, 2026
Updated Apr 3, 2026
Reserved Apr 3, 2026
Link CVE-2026-5474
CISA Vulnrichment
Updated Apr 3, 2026
ENISA EUVD
EUVD-2026-18807 Assigner VulDB
Published Apr 3, 2026
Updated Apr 3, 2026
Exploited since n/a
Link EUVD-2026-18807