CRITICAL
MOOS-IvP through 24.8.1 Buffer Overflow in IvP Function String Decoders
Published Sep 3, 2026
9.3
CRITICALCVSS 4.0
EPSS 1.17%
Description
MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker-controlled length fields without validation. Attackers can craft malicious encoded strings with mismatched declared and actual field lengths to overflow heap and stack buffers, potentially achieving remote code execution through MOOS variables or alog files.
Affected products
-
- Version 0StatusaffectedConstraints<=24.8.1
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/moos-ivp/moos-ivp product
- https://github.com/moos-ivp/moos-ivp/blob/1de9ae146cd63c209e8c3fd81611a4ed2472971b/ivp/src/lib_ivpbuild/FunctionEncoder.cpp#L310 technical-description
- https://github.com/moos-ivp/moos-ivp/commit/81ca795fcfd62b42002d277f5a2390f4c8ab8c7f patch
- https://github.com/moos-ivp/moos-ivp/pull/125 issue-trackingpatch
- https://www.vulncheck.com/advisories/moos-ivp-through-24.8.1-buffer-overflow-in-ivp-function-string-decoders third-party-advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 3, 2026
Updated Sep 4, 2026
Reserved Sep 3, 2026
Link CVE-2026-85437
CISA Vulnrichment
Updated Sep 4, 2026