CRITICALVulnerability
CVE-2026-85438
MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used as allocation sizes and loop bounds without validation. Attackers can supply crafted payloads with mismatched dimension values to write attacker-controlled doubles past the end of the IvPBox weight array, causing memory corruption and potential code execution.
Properties
- severity
- CRITICAL
- score
- 9.8
- cve_id
- CVE-2026-85438
- signal_observed_at
- 2026-09-15T21:20:01+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- published_at
- 2026-09-03T23:17:23.270
- last_modified
- 2026-09-14T14:17:13.980
Related Entities (2)
HAS_WEAKNESS (1)
→[Weakness]Integer Overflow or Wraparound
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph