---
id: CVE-2026-82479
title: A vulnerability was identified in NASA cFS up to 7.0.1
summary: >-
  A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the
  function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the
  component SBN TCP Module. Such manipulation of the argument MsgSz leads to
  buffer overf…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-119
  - CWE-120
published: '2026-08-30'
updated: '2026-08-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82479'
references:
  - url: 'https://vuldb.com/cve/CVE-2026-82479'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/888017'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/397029'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/397029/cti'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00379
epssPercentile: 0.29119
ingestedAt: '2026-08-30T14:53:42.787Z'
---

## Overview

A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
