Junglewise Threat Intelligence

CVE-2026-76987: liftoff-sr CIPster memory corruption in attribute handling

CVE-2026-76987 · Severity: high · CVSS 7.3 · Published 2026-08-20

Technologies: Liftoff-Sr CIPster.

Executive brief

CIPster is an Ethernet/IP protocol stack used in industrial I/O adapter devices. A memory corruption vulnerability in the attribute handling logic allows a remote attacker to read arbitrary memory or write out of bounds, potentially compromising device availability and control.

Technical details

The vulnerability is a buffer overflow in the CipAttribute::GetAttrData and CipAttribute::SetAttrData functions (ciptypes.h). The root cause is insufficient bounds checking on byte-array attribute length: a remote attacker can send a SetAttributeSingle message with an attacker-controlled length value that is not validated against the actual buffer capacity. This allows out-of-bounds reads (information disclosure) and out-of-bounds writes (memory corruption). The attack is network-reachable and requires no authentication. The patch (commit e745d9d4a8ca3a13689066983a1269fe1e567674) introduces a CipByteArray type that tracks capacity immutably, preventing length inflation past the allocation.

Affected products

  • liftoff-sr CIPster before commit e745d9d4a8ca3a13689066983a1269fe1e567674

Timeline

  • 2026-08-20: disclosed
  • 2026-06-01: patched: Patch commit e745d9d4a8ca3a13689066983a1269fe1e567674

References