Integer Overflow Vulnerability in NASA cFS Software by NASA
CVE-2026-5476
2.1LOW
What is CVE-2026-5476?
A significant integer overflow vulnerability has been identified in NASA's cFS software, specifically in the CFE_TBL_ValidateCodecLoadSize function within the cfe_tbl_passthru_codec.c file. This flaw affects versions of NASA cFS up to 7.0.0 on 32-bit systems, and while the complexity of exploiting this vulnerability is classified as high, the actual exploitability is noted to be challenging. A resolution is in the pipeline with plans for a fix in an upcoming version milestone.
Affected Version(s)
cFS 7.0
References
CVSS V4
Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
0rbitingZer0 (VulDB User)
VulDB CNA Team
