Buffer Overflow Vulnerability in MOOS-IvP by MOOS-IvP
CVE-2026-85438
9.3CRITICAL
What is CVE-2026-85438?
The MOOS-IvP product versions up to 24.8.1 are vulnerable to a buffer overflow due to improper handling of dimensions, pieces, and degrees when processing encoded BHV_IPF payloads. Specifically, the StringToIvPFunction() function allows attackers to craft payloads with arbitrary dimension specifications that exceed the expected bounds. This can lead to a situation where attacker-controlled values are written past the end of the IvPBox weight array, resulting in memory corruption and the potential for execution of arbitrary code.
Affected Version(s)
moos-ivp 0 <= 24.8.1
