Sceawere
Vulnerability Detail
CVE-2026-105164UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
NASA cFS Out-of-Bounds Read
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 2.7
- Creation Date
- 20h ago
- Vendor
- NASA
- Product
- cFS
- Attack Type
- Out-of-Bounds Read
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw has been found in NASA cFS up to 7.0.1. This issue affects the function CFE_FS_ParseInputFileNameEx of the file cfe/modules/fs/fsw/src/cfe_fs_api.c. This manipulation causes out-of-bounds read. Remote exploitation of the attack is possible. The pull request to fix this issue awaits acceptance.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "2.7",
"pubDate": "2026-10-04T22:16:59.490Z",
"pubdate": "2026-10-04T22:16:59.490Z",
"executiveSummary": "A critical out-of-bounds read vulnerability has been identified in the NASA cFS (Core Flight System) framework, specifically affecting versions up to 7.0.1.\nThe flaw resides within the CFE_FS_ParseInputFileNameEx function, located in the file cfe/modules/fs/fsw/src/cfe_fs_api.c.\nThis vulnerability is triggered when the function processes a specially crafted filename, resulting in unauthorized memory access.\nThe nature of this flaw allows for potential remote exploitation, posing a significant risk to the integrity and stability of the underlying flight software system.\nBy manipulating input filename parameters, an attacker may be able to read sensitive memory regions, potentially leading to information disclosure or system crashes.\nSuccessful exploitation depends on the attacker's ability to supply malicious input to the affected API. As this is a core component, compromise could lead to cascading failures in mission-critical flight software applications.",
"technicalDetails": "The vulnerability is rooted in an improper boundary check within the CFE_FS_ParseInputFileNameEx function in cfe/modules/fs/fsw/src/cfe_fs_api.c. This function is responsible for parsing and validating filesystem input filenames provided to the cFS Core Flight Executive.\nThe flaw occurs during the filename processing logic where the system fails to adequately sanitize or verify the length of the input string relative to the fixed-size buffers or memory pointers assigned to the file operation. When the input filename exceeds the expected boundaries, the function performs read operations beyond the allocated memory segment.\nExploitation is achieved by transmitting a malformed filename string through an interface that communicates with the cFS filesystem module. The attacker does not require local access, as the function can be reached through remote command pathways provided the cFS implementation exposes file management interfaces over the network or via telecommand links.\nWhen CFE_FS_ParseInputFileNameEx attempts to copy or parse the overly long filename, it reads data from the adjacent memory space into process registers or return buffers. This allows an attacker to leak sensitive information residing in the memory adjacent to the vulnerable buffer, such as stack cookies, pointers, or system configuration data.\nBecause NASA cFS is designed for embedded flight environments, memory layout is often deterministic. An attacker can leverage this predictability to craft a payload that targets specific memory offsets, facilitating controlled data extraction. The impact of such an OOB read includes the compromise of system-wide secrecy, potentially revealing cryptographic keys or operational parameters essential for maintaining the craft's safety and integrity.\nFurthermore, the out-of-bounds read can result in a segmentation fault or memory corruption if the read operation accesses unmapped memory regions or causes the process to enter an undefined state, leading to a denial-of-service (DoS) condition. In a mission-critical flight environment, this service interruption could force a processor reset, potentially resulting in the loss of telemetry or command capability for the duration of the reboot sequence."
}