CVE-2026-85445: MOOS-IvP through 24.8.1 BHV_IPF Demultiplexer Memory Exhaustion via Packet Count

Published Sep 3, 2026
·
Updated

MOOS-IvP through 24.8.1 contains a denial of service vulnerability in the Demuxer::addMuxPacket() function that trusts the packet count declared in mux headers without validation. Attackers can declare arbitrarily large packet counts to trigger unbounded memory allocation, exhausting system resources and causing service unavailability.

Affected Software

1 affected component
MOOS-IvP<=24.8.1

Event History

Sep 3, 2026
CVE Published
via MITRE·10:38 PM
Data Sourced
via MITRE·10:38 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What access does an attacker need to exploit this issue?

The vulnerability is remotely exploitable over the network and requires no privileges or user interaction. An attacker needs to send mux packets with an arbitrarily large packet count declared in the header.

2

What is the expected impact of successful exploitation?

Successful exploitation can cause unbounded memory allocation and exhaust system resources, making the affected service unavailable. The provided impact information indicates availability impact only, with no stated confidentiality or integrity impact.

3

Which deployments should be prioritized for remediation?

Prioritize MOOS-IvP deployments through version 24.8.1 that accept mux packets from untrusted or network-accessible sources. The provided data does not state whether any particular default configuration exposes the vulnerable packet-processing path.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203