Description
A vulnerability was determined in NASA cFS up to 7.0.0. This impacts the function CFE_SB_TransmitMsg of the file cfe_sb_priv.c of the component CCSDS Header Size Handler. Executing a manipulation can lead to memory corruption. The project was informed of the problem early through an issue report but has not responded yet.
Problem types
Product status
Timeline
| 2026-04-03: | Advisory disclosed |
| 2026-04-03: | VulDB entry created |
| 2026-04-03: | VulDB entry last update |
Credits
0rbitingZer0 (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/355079 (VDB-355079 | NASA cFS CCSDS Header Size cfe_sb_priv.c CFE_SB_TransmitMsg memory corruption)
vuldb.com/vuln/355079/cti (VDB-355079 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/781951 (Submit #781951 | NASA cFS 7.0.0 CFE_SB_TransmitMsg memcpy trusts CCSDS header size without sourc)
github.com/nasa/cFS/issues/953
github.com/nasa/cFS/