CVE-2026-82480
Received Received - Intake

Integer Underflow in NASA cFS up to 7.0.1

Vulnerability report for CVE-2026-82480, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-30

Last updated on: 2026-08-30

Assigner: VulDB

Description

A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize results in integer underflow. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-30
Last Modified
2026-08-30
Generated
2026-08-30
AI Q&A
2026-08-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nasa cfs to 7.0.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-191 The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
CWE-189

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an integer underflow flaw in NASA's cFS up to version 7.0.1. It exists in the CFE_SB_GetUserDataLength function within the cFE Software Bus component. An attacker can remotely manipulate the TotalMsgSize/HdrSize argument to trigger the underflow, potentially leading to unexpected behavior or crashes.

Impact Analysis

The impact includes potential denial of service due to crashes, unauthorized access if exploited to manipulate data, or unexpected system behavior. Since the attack can be initiated remotely, systems running vulnerable cFS versions are at risk without proper mitigation.

Compliance Impact

This vulnerability involves an integer underflow in NASA cFS up to 7.0.1, which could allow remote manipulation of message sizes. While not directly tied to GDPR or HIPAA, such flaws may lead to unauthorized data access or integrity issues, potentially violating confidentiality requirements in these standards.

Mitigation Strategies

Update NASA cFS to a version beyond 7.0.1 to address the integer underflow issue in CFE_SB_GetUserDataLength. If an update is not available, restrict network access to the affected component and monitor for unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82480. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart