CVE-2026-5476 describes an integer overflow vulnerability in the CFE_TBL_ValidateCodecLoadSize function of NASA cFS up to version 7.0.0 on 32-bit systems. This Medium severity vulnerability (CVSS 4.6) requires adjacent network access and low privileges, but has high attack complexity, resulting in low impacts to confidentiality, integrity, and availability. Exploitation is considered difficult, with no public exploit code or active exploitation observed, and community attention is minimal. A fix for this issue is planned for an upcoming version milestone of the project.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.0.0CPE matchmatch criteria | cpe:2.3:a:nasa:core_flight_system:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.