Back

HIGH

MZ Automation libiec61850 Out-of-bounds Read

Published Jul 30, 2026

Description

The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition.

Affected products

Remediation

Vendor solution

MZ Automation GmbH recommends that users update to version 1.6.2.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner icscert
Published Jul 30, 2026
Updated Jul 31, 2026
Reserved Jul 27, 2026

CISA Vulnrichment

Updated Jul 31, 2026

NVD

Status Deferred
Modified Sep 3, 2026

Red Hat

No data

ENISA EUVD

Assigner icscert
Published Jul 30, 2026
Updated Jul 31, 2026

GitHub

No data