CVE-2026-18064: NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference
An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a denial-of-service condition and processor reset.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18064?
The severity of CVE-2026-18064 is rated as high with a score of 7.5.
How do I fix CVE-2026-18064?
To fix CVE-2026-18064, upgrade the NASA Core Flight System (cFS) Health & Safety (HS) Application to a version that patches the NULL pointer dereference vulnerability.
What type of vulnerability is CVE-2026-18064?
CVE-2026-18064 is classified as a NULL Pointer Dereference vulnerability.
What versions are affected by CVE-2026-18064?
CVE-2026-18064 affects versions of the NASA Core Flight System (cFS) Health & Safety (HS) Application through 7.0.1.
What can an attacker do with CVE-2026-18064?
An attacker who triggers the specific command under certain conditions could potentially cause the Health & Safety application to crash.