CVE-2026-66369: MZ Automation libiec61850 Out-of-bounds Read
The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly, resulting in a heap out-of-bounds read. On affected platforms, this condition reliably terminates the subscriber process and causes a denial-of-service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MZ Automation libiec61850to a version that resolves this vulnerability.Fixed in 1.6.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66369?
CVE-2026-66369 has a medium severity score of 6.5.
What type of vulnerability is CVE-2026-66369?
CVE-2026-66369 is an out-of-bounds read vulnerability due to an off-by-one boundary-handling flaw in the GOOSE parser.
How can CVE-2026-66369 be exploited?
CVE-2026-66369 can be triggered by sending a single unauthenticated Layer-2 multicast frame on the process bus.
What software is affected by CVE-2026-66369?
CVE-2026-66369 specifically affects the libIEC61850 software.
What impact does CVE-2026-66369 have on systems?
CVE-2026-66369 can lead to a potential heap out-of-bounds read, impacting system integrity and availability.