(cFS) Health and Safety (HS) application leaves a separate NULL pointer
dereference reachable in versions through 7.0.1. An attacker who can
trigger the affected command under specific conditions could cause the
HS application to crash, resulting in a denial-of-service condition and
processor reset.
Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
NASA reports that an official fix is currently under development and is expected to be included in a future software release. As an interim mitigation, users can update their HS app from the HS repo ( https://github.com/nasa/HS ) to the latest dev branch. The fix is in the dev branch starting at commit 828855f971db4b6714367ed0a970f52dbeab2965
Thu, 30 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a denial-of-service condition and processor reset. | |
| Title | NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-07-30T21:35:14.061Z
Reserved: 2026-07-28T14:10:13.503Z
Link: CVE-2026-18064
No data.
No data.
No data.
OpenCVE Enrichment
No data.