Junglewise Threat Intelligence

CVE-2026-82480: NASA cFS integer underflow in CFE_SB_GetUserDataLength

CVE-2026-82480 · Severity: high · CVSS 7.4 · Published 2026-08-30

Vendors: Nasa.

Executive brief

NASA's cFS (core Flight System) is spacecraft flight software used to manage and control satellite and spacecraft operations. An integer underflow vulnerability in the Software Bus component allows remote attackers to manipulate message size calculations, potentially causing denial of service, memory corruption, or arbitrary code execution on mission-critical systems.

Technical details

The vulnerability is an integer underflow in the CFE_SB_GetUserDataLength function within src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c. An attacker can manipulate the TotalMsgSize or HdrSize arguments to trigger an underflow condition, causing incorrect user data length calculations. The flaw is remotely exploitable over the network with no authentication required. Successful exploitation could lead to denial of service, buffer overflows, or arbitrary code execution. The vendor (NASA) was contacted early but provided no response or patch at the time of disclosure.

Affected products

  • NASA cFS up to 7.0.1

Timeline

  • 2026-08-30: disclosed
  • 2026-08-30: advisory

References

Related threats