CVE-2026-5476: NASA cFS cfe_tbl_passthru_codec.c CFE_TBL_ValidateCodecLoadSize integer overflow
A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit. Affected is the function CFETBLValidateCodecLoadSize of the file cfe/modules/tbl/fsw/src/cfetblpassthrucodec.c. The manipulation leads to integer overflow. The complexity of an attack is rather high. The exploitability is told to be difficult. A fix is planned for the upcoming version milestone of the project.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5476?
CVE-2026-5476 is categorized as a high severity vulnerability due to the potential for integer overflow exploitation.
How do I fix CVE-2026-5476?
To remediate CVE-2026-5476, update NASA cFS to a version later than 7.0.0 where this vulnerability has been addressed.
What systems are affected by CVE-2026-5476?
CVE-2026-5476 impacts versions of NASA cFS up to and including 7.0.0 on 32-bit systems.
What can happen if CVE-2026-5476 is exploited?
Exploitation of CVE-2026-5476 could lead to unexpected behavior or crashes within applications utilizing the affected function.
Which function is responsible for CVE-2026-5476?
CVE-2026-5476 is associated with the function CFE_TBL_ValidateCodecLoadSize in the cfe_tbl_passthru_codec.c file.