Heap Overflow Vulnerability in MOOS Core-MOOS by MOOS
CVE-2026-85440
9.3CRITICAL
What is CVE-2026-85440?
The MOOS core-moos versions up to and including 10.4.0 are susceptible to a pre-authentication heap overflow due to improper handling of packet lengths in the MOOSCommPkt functionality. Specifically, the vulnerability arises when attackers exploit a signed integer check in the InflateTo() method, allowing them to declare a negative packet length. This can result in arbitrary data being written to the heap during the HandShake phase of communication, potentially compromising the integrity of the system. This issue raises significant security concerns and requires immediate attention to safeguard affected installations.
Affected Version(s)
core-moos 0 <= 10.4.0
