{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/network-vulnerability/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:moos-ivp:core-moos:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-85440"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["core-moos (\u003c= 10.4.0)"],"_cs_severities":["critical"],"_cs_tags":["cve","authentication-bypass","middleware","denial-of-service","network-vulnerability","vulnerability","network-security","remote-access"],"_cs_type":"advisory","_cs_vendors":["MOOS-IvP","MOOS"],"content_html":"\u003cp\u003eMOOS core-moos versions up to 10.4.0 contain a critical heap-based buffer overflow vulnerability within the MOOSCommPkt packet handling logic. The issue resides in the HandShake phase, which occurs before authentication is established. An unauthenticated remote attacker can supply a negative value in the packet length field, which bypasses existing signed integer checks within the InflateTo() function. This discrepancy leads to an improper size conversion when the data is passed to the recv() function, causing a heap overflow of a four-byte buffer. Successful exploitation allows an attacker to write arbitrary data into the process memory, potentially leading to remote code execution or application crashes. Given the pre-authentication nature of this flaw, defenders should prioritize patching or restricting access to the MOOS communication ports.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes a TCP/IP connection to the target host on the MOOS communication port.\u003c/li\u003e\n\u003cli\u003eAttacker initiates the HandShake phase of the communication protocol.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious packet header containing a negative integer in the packet length field.\u003c/li\u003e\n\u003cli\u003eThe victim application receives the malicious packet via the InflateTo() function.\u003c/li\u003e\n\u003cli\u003eThe vulnerability in the signed integer check allows the negative length to pass validation.\u003c/li\u003e\n\u003cli\u003eThe application performs a heap-based memory allocation based on the unchecked length.\u003c/li\u003e\n\u003cli\u003eThe recv() function processes the attacker-supplied data, resulting in a heap overflow of the internal four-byte buffer.\u003c/li\u003e\n\u003cli\u003eAttacker achieves arbitrary memory write, leading to remote code execution or process termination.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated remote attackers to execute arbitrary code or cause a denial-of-service condition on affected MOOS installations. This affects systems utilizing MOOS core-moos versions 10.4.0 and earlier. Organizations relying on this software for underwater vehicle communication or similar robotics research environments are at high risk if instances are exposed to untrusted networks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch core-moos by upgrading to a version exceeding 10.4.0 immediately upon release of vendor updates.\u003c/li\u003e\n\u003cli\u003eUntil patching is possible, restrict access to MOOS communication ports via host-based firewalls or network access control lists to known trusted endpoints only.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for anomalous packet headers directed toward MOOS services, specifically looking for TCP streams containing negative length identifiers in the handshake phase.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T01:24:01Z","date_published":"2026-09-03T23:25:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-moos-heap-overflow/","summary":"A pre-authentication heap overflow vulnerability in the MOOSCommPkt packet handling of MOOS core-moos versions up to 10.4.0 allows remote unauthenticated attackers to perform arbitrary memory writes via crafted packets.","title":"CVE-2026-85440: Heap Overflow in MOOS core-moos","url":"https://feed.craftedsignal.io/briefs/2026-09-moos-heap-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Network-Vulnerability","version":"https://jsonfeed.org/version/1.1"}