Junglewise Threat Intelligence

CVE-2026-41144: NASA F Prime integer overflow and arbitrary file write in FileUplink

CVE-2026-41144 · Severity: info · CVSS 0 · Published 2026-04-22

Vendors: Nasa.

Executive brief

NASA's F Prime (F´) framework, used for developing spaceflight and embedded software, contains a vulnerability that allows an attacker to write data to any file on the system. By sending a specially crafted data packet, an attacker can bypass security checks and overwrite critical system files or application code. This could lead to a complete takeover of the embedded device, potentially causing mission failure or permanent hardware damage.

Technical details

An integer overflow vulnerability exists in the FileUplink component of the F Prime framework. The bounds check 'byteOffset + dataSize > fileSize' uses 32-bit unsigned integer addition, which can be made to wrap around to a small value by providing a large byteOffset. This bypasses the size validation check while the subsequent file write operation uses the original large offset. When combined with a lack of path sanitization in Svc/FileUplink/File.cpp, an unauthenticated network attacker can achieve arbitrary file writes at arbitrary offsets. This can be leveraged to achieve remote code execution (RCE) on the embedded target. The issue is addressed in version 4.2.0.

Affected products

  • NASA F Prime (F´) < 4.2.0

Timeline

  • 2026-03-31: patched: Fix committed to GitHub repository
  • 2026-04-14: advisory: GitHub security advisory published
  • 2026-04-22: disclosed: CVE published to NVD

References