Junglewise Threat Intelligence

CVE-2026-82479: NASA cFS buffer overflow in SBN TCP Module

CVE-2026-82479 · Severity: medium · CVSS 6.3 · Published 2026-08-30

Vendors: Nasa.

Executive brief

NASA's cFS (core Flight Software) is a reusable flight software framework used in spacecraft and aerospace systems. A buffer overflow vulnerability in the TCP networking module could allow an attacker on the local network to crash the system or potentially execute arbitrary code, compromising mission-critical operations.

Technical details

A buffer overflow vulnerability exists in the OS_read function of the SBN (Software Bus Network) TCP Module in modules/protocol/tcp/fsw/src/sbn_tcp_if.c. The vulnerability is triggered through improper handling of the MsgSz argument, which fails to validate input size before writing to a buffer. The attack vector is adjacent network, requiring the attacker to be on the local network. An attacker can cause a denial of service or potentially achieve code execution. No patch availability information is currently available; the vendor was contacted early but did not respond.

Affected products

  • NASA cFS up to 7.0.1

Timeline

  • 2026-08-30: disclosed

References

Related threats