Libcsp is a compact, specialized communications protocol library for embedded and space systems, with its vulnerability exposure concentrated in the core library product itself. The durable signal centers on memory-safety weaknesses including buffer-boundary violations and classic buffer overflows, reflecting the low-level packet handling and C-language implementation characteristic of protocol stacks operating in resource-constrained environments. Current severity, exploitation status, and detailed exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libcsp over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-8598CRITICAL Buffer overflow in the zmq interface in csp_if_zmqhub.c in the libcsp library v1.4 and earlier allows hostile computers connected via a zmq interface to execute arbitrary code via | Oct 28, 2016 | 9.8 | 30 | NO | NO |
CVE-2016-8597CRITICAL Buffer overflow in the csp_sfp_recv_fp in csp_sfp.c in the libcsp library v1.4 and earlier allows hostile components with network access to the SFP underlying network layers to exe | Oct 28, 2016 | 9.8 | 30 | NO | NO |
CVE-2016-8596CRITICAL Buffer overflow in the csp_can_process_frame in csp_if_can.c in the libcsp library v1.4 and earlier allows hostile components connected to the canbus to execute arbitrary code via | Oct 28, 2016 | 9.8 | 30 | NO | NO |
CVE-2025-51824MEDIUM libcsp 2.0 is vulnerable to Buffer Overflow in the csp_usart_open() function at drivers/usart/zephyr.c. | Aug 11, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-51823MEDIUM libcsp 2.0 is vulnerable to Buffer Overflow in the csp_eth_init() function due to improper handling of the ifname parameter. The function uses strcpy to copy the interface name int | Aug 11, 2025 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libcsp.
Media articles that mention a CVE ID that affects a product developed by Libcsp — matched by CVE ID, not by vendor name.