MZ Automation libiec61850 Out-of-bounds Read
Published Jul 30, 2026
7.1
HIGHCVSS 4.0
EPSS 0.29%
Description
The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition.
Affected products
-
Affected
- ≥ 0, < 1.6.2
Unaffected
- 1.6.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| MZ Automation GmbH | Libiec61850 | unaffected | Affected
Unaffected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
MZ Automation GmbH recommends that users update to version 1.6.2.
References (3)
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data