<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:nasa:core_flight_system:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3anasacore_flight_system/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 30 Aug 2026 07:09:07 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3anasacore_flight_system/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Integer Underflow Vulnerability in NASA cFS cFE Software Bus</title><link>https://feed.craftedsignal.io/briefs/2026-08-nasa-cfs-integer-underflow/</link><pubDate>Sun, 30 Aug 2026 07:09:07 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-nasa-cfs-integer-underflow/</guid><description>An integer underflow vulnerability in the CFE_SB_GetUserDataLength function of the NASA cFS cFE Software Bus (up to version 7.0.1) allows remote attackers to trigger memory corruption via manipulated message size arguments.</description><content:encoded><![CDATA[<p>A security vulnerability (CVE-2026-82480) has been identified in the NASA Core Flight System (cFS), specifically within the cFE Software Bus component. The issue resides in the CFE_SB_GetUserDataLength function located in 'src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c'. The vulnerability is triggered by manipulating the 'TotalMsgSize' and 'HdrSize' arguments, which leads to an integer underflow condition. This flaw is remotely exploitable, posing a risk to mission-critical systems relying on the cFS architecture. As the vulnerability resides in a core messaging component, successful exploitation could potentially lead to system instability, denial of service, or further memory-based exploitation depending on how the Software Bus processes the resulting corrupted data. NASA has not provided a response or a patch to the disclosure at this time.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability affects NASA cFS versions up to 7.0.1. Systems utilizing the cFE Software Bus for message routing and communication are at risk of remote exploitation. Given the nature of flight systems, successful exploitation could lead to critical system crashes or process termination, potentially impacting the operational integrity of the host platform.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the internal assessment of flight software dependencies for exposure to the cFE Software Bus message processing logic. Since no patch is currently available, implement strict input validation and bounds checking for all incoming messages reaching the cFE Software Bus to intercept manipulated 'TotalMsgSize' or 'HdrSize' values before they reach the vulnerable function. Monitor system logs for unexpected software bus service restarts or memory-related exception signals that may indicate an attempt to trigger this vulnerability.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>