<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-76987 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-76987/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 20 Aug 2026 15:15:29 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-76987/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Memory Corruption Vulnerability in liftoff-sr CIPster</title><link>https://feed.craftedsignal.io/briefs/2026-08-cve-2026-76987/</link><pubDate>Thu, 20 Aug 2026 15:15:29 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-cve-2026-76987/</guid><description>A remote memory corruption vulnerability in the Generic Attribute Logic component of liftoff-sr CIPster allows for unauthenticated exploitation via the GetAttrData and SetAttrData functions.</description><content:encoded><![CDATA[<p>A memory corruption vulnerability, tracked as CVE-2026-76987, affects the Generic Attribute Logic component within liftoff-sr CIPster (specifically version 1802525be27d33e19a9a83c163e331a1d13b1892). The flaw originates in the CipAttribute::GetAttrData and CipAttribute::SetAttrData functions located within the ciptypes.h header file. This vulnerability is significant because it can be triggered remotely without authentication. The vulnerability has been publicly disclosed, and exploit code is available, increasing the risk of exploitation. Defenders must verify the version of the CIPster component in use and apply the recommended patch e745d9d4a8ca3a13689066983a1269fe1e567674 immediately to prevent potential remote code execution or application crashes resulting from memory corruption.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a high risk to availability and system integrity due to the potential for memory corruption. Attackers can remotely exploit this flaw, which may lead to service disruption (denial of service) or potential arbitrary code execution depending on the environment. The scope of impact includes any deployment utilizing the vulnerable CIPster component, particularly those exposed to network traffic.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all instances of liftoff-sr CIPster within the environment and verify if the commit 1802525be27d33e19a9a83c163e331a1d13b1892 is present.</li>
<li>Apply patch e745d9d4a8ca3a13689066983a1269fe1e567674 to all affected CIPster components.</li>
<li>Restrict network access to services utilizing the Generic Attribute Logic component if patching cannot be performed immediately.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>cve-2026-76987</category><category>memory-corruption</category></item></channel></rss>