{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cfs--7.0.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nasa:core_flight_system:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-82480"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cFS (\u003c= 7.0.1)","cFE Software Bus (\u003c= 7.0.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["NASA"],"content_html":"\u003cp\u003eA security vulnerability (CVE-2026-82480) has been identified in the NASA Core Flight System (cFS), specifically within the cFE Software Bus component. The issue resides in the CFE_SB_GetUserDataLength function located in 'src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c'. The vulnerability is triggered by manipulating the 'TotalMsgSize' and 'HdrSize' arguments, which leads to an integer underflow condition. This flaw is remotely exploitable, posing a risk to mission-critical systems relying on the cFS architecture. As the vulnerability resides in a core messaging component, successful exploitation could potentially lead to system instability, denial of service, or further memory-based exploitation depending on how the Software Bus processes the resulting corrupted data. NASA has not provided a response or a patch to the disclosure at this time.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability affects NASA cFS versions up to 7.0.1. Systems utilizing the cFE Software Bus for message routing and communication are at risk of remote exploitation. Given the nature of flight systems, successful exploitation could lead to critical system crashes or process termination, potentially impacting the operational integrity of the host platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the internal assessment of flight software dependencies for exposure to the cFE Software Bus message processing logic. Since no patch is currently available, implement strict input validation and bounds checking for all incoming messages reaching the cFE Software Bus to intercept manipulated 'TotalMsgSize' or 'HdrSize' values before they reach the vulnerable function. Monitor system logs for unexpected software bus service restarts or memory-related exception signals that may indicate an attempt to trigger this vulnerability.\u003c/p\u003e\n","date_modified":"2026-08-30T07:09:07Z","date_published":"2026-08-30T07:09:07Z","id":"https://feed.craftedsignal.io/briefs/2026-08-nasa-cfs-integer-underflow/","summary":"An integer underflow vulnerability in the CFE_SB_GetUserDataLength function of the NASA cFS cFE Software Bus (up to version 7.0.1) allows remote attackers to trigger memory corruption via manipulated message size arguments.","title":"Integer Underflow Vulnerability in NASA cFS cFE Software Bus","url":"https://feed.craftedsignal.io/briefs/2026-08-nasa-cfs-integer-underflow/"}],"language":"en","title":"CraftedSignal Threat Feed - CFS (\u003c= 7.0.1)","version":"https://jsonfeed.org/version/1.1"}