Out-of-Bounds Read Vulnerability in TIER IV Nebula from Tier IV
CVE-2026-74238
8.7HIGH
What is CVE-2026-74238?
TIER IV Nebula versions up to 1.2.0 contain an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function. This flaw allows unauthenticated remote attackers to exploit the decoder by sending short malformed UDP datagrams. The vulnerability permits the attacker to read past the end of a UDP buffer into adjacent heap memory. This can lead to unauthorized data being published in downstream PointCloud2 messages consumed by Autoware nodes, potentially impacting the integrity and security of data processing in autonomous systems.
Affected Version(s)
nebula 0 <= 1.2.0
