CVE-2026-82480 | NASA cFS up to 7.0.1 cFE Software Bus cfe_sb_util.c CFE_SB_GetUserDataLength TotalMsgSize/HdrSize integer underflow

SecurityVulns

A vulnerability has been found in NASA cFS up to 7.0.1 and classified as critical. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize results in integer underflow.

This vulnerability is cataloged as CVE-2026-82480. It is possible to initiate the attack remotely. There is no exploit available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More