CVE-2026-82480: NASA cFS cFE Software Bus cfe_sb_util.c CFE_SB_GetUserDataLength integer underflow

Published Aug 30, 2026
·
Updated

A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFESBGetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfesbutil.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize results in integer underflow. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

1 affected component
nasa cFE Software Bus<=7.0.1

Event History

Aug 30, 2026
CVE Published
via MITRE·05:30 AM
Data Sourced
via MITRE·05:30 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to remote exploitation?

Deployments using the affected cFE Software Bus component in NASA cFS up to version 7.0.1 are in scope. The issue can be triggered remotely, though the available information does not identify the specific network interface or deployment configuration required.

2

What access does an attacker need?

The severity vector indicates low privileges are required and no user interaction is required. Exploitation involves manipulating the TotalMsgSize and HdrSize arguments passed to CFE_SB_GetUserDataLength.

3

Is a vendor fix available?

No vendor response is reported in the available information. A fixed version or official mitigation is not identified.

4

How can I determine whether my environment is affected?

Check whether your NASA cFS deployment uses the cFE Software Bus component and is running version 7.0.1 or earlier. The affected function is CFE_SB_GetUserDataLength in src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203