Out-of-Bounds Read Vulnerability in NASA cFS Product
CVE-2026-105164
5.1MEDIUM
What is CVE-2026-105164?
A vulnerability has been identified in NASA's Core Flight System (cFS) versions up to 7.0.1. The flaw resides in the function CFE_FS_ParseInputFileNameEx located in the file cfe/modules/fs/fsw/src/cfe_fs_api.c, leading to an out-of-bounds read condition. This weakness could be exploited remotely, potentially compromising the system's integrity and confidentiality. A pull request addressing this issue is currently pending acceptance, highlighting the importance of prompt intervention to mitigate risks.
Affected Version(s)
cFS 7.0.0
cFS 7.0.1
