Executive brief
NASA's cFS (core Flight Software) is a reusable flight software framework used in spacecraft and aerospace systems. A buffer overflow vulnerability in the TCP networking module could allow an attacker on the local network to crash the system or potentially execute arbitrary code, compromising mission-critical operations.
Technical details
A buffer overflow vulnerability exists in the OS_read function of the SBN (Software Bus Network) TCP Module in modules/protocol/tcp/fsw/src/sbn_tcp_if.c. The vulnerability is triggered through improper handling of the MsgSz argument, which fails to validate input size before writing to a buffer. The attack vector is adjacent network, requiring the attacker to be on the local network. An attacker can cause a denial of service or potentially achieve code execution. No patch availability information is currently available; the vendor was contacted early but did not respond.
Affected products
- NASA cFS up to 7.0.1
Timeline
- 2026-08-30: disclosed