CVE-2026-15352: NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference
A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NASA Core Flight System (cFS) Health & Safety (HS) applicationto a version that resolves this vulnerability.Fixed in v7.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15352?
CVE-2026-15352 has a severity score of 7.5, categorized as high.
How does CVE-2026-15352 affect NASA's Core Flight System (cFS)?
CVE-2026-15352 causes a NULL pointer dereference in the Health & Safety application, leading to a denial of service due to application crashes.
How can I mitigate the risks associated with CVE-2026-15352?
Mitigation involves updating the NASA Core Flight System (cFS) Health & Safety application to version 7.0.1 or later.
What is the impact of exploiting CVE-2026-15352?
Exploiting CVE-2026-15352 can lead to a segmentation fault, resulting in service interruption for the Health & Safety application.
Is there a patch available for CVE-2026-15352?
Yes, a patch is available through the release of version 7.0.1 of the NASA Core Flight System (cFS) Health & Safety application.