<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Maritime - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/maritime/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 03 Sep 2026 23:25:05 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/maritime/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Buffer Overflow Vulnerabilities in MOOS-IvP</title><link>https://feed.craftedsignal.io/briefs/2026-09-moos-ivp-buffer-overflow/</link><pubDate>Thu, 03 Sep 2026 23:25:05 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-moos-ivp-buffer-overflow/</guid><description>Multiple buffer overflow vulnerabilities in MOOS-IvP versions up to 24.8.1 allow for remote code execution via malformed IvP function strings.</description><content:encoded><![CDATA[<p>MOOS-IvP through version 24.8.1 contains multiple buffer overflow vulnerabilities located within its IvP function string decoders. The vulnerability arises due to the application's failure to adequately validate length fields provided in attacker-controlled input. By crafting malicious encoded strings where the declared field length differs significantly from the actual field length, an attacker can induce heap or stack buffer overflows. These memory corruption events can be leveraged to achieve arbitrary remote code execution. The vulnerability is triggered when the affected components process malicious MOOS variables or malformed alog files, which are central to the MOOS-IvP communication and logging architecture. Defenders should prioritize patching, as these vulnerabilities are classified with a CVSS v3.1 base score of 9.8, indicating high potential for exploitation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities allows an attacker to execute arbitrary code with the privileges of the MOOS-IvP process. In many deployments, these processes operate within critical autonomous systems or research environments. If exploited, an attacker could gain persistent access, exfiltrate sensitive mission data, or disrupt the operation of underwater autonomous vehicles and other marine robotic systems using the MOOS-IvP framework.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of MOOS-IvP to version 24.8.2 or later to address the vulnerable IvP function string decoders identified in CVE-2026-85437.</li>
<li>Audit all external inputs feeding into MOOS variables and restrict access to alog files to trusted administrative users only.</li>
<li>Monitor process integrity for abnormal crashes or memory access violations that might indicate attempted exploitation of these buffer overflows.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>cve</category><category>rce</category><category>memory-corruption</category><category>buffer-overflow</category><category>research-robotics</category><category>cve-2026-85438</category><category>remote-code-execution</category><category>command-injection</category><category>denial-of-service</category><category>middleware</category><category>maritime</category></item></channel></rss>