(cFS) Health and Safety (HS) application leaves a separate NULL pointer
dereference reachable in versions through 7.0.1. An attacker who can
trigger the affected command under specific conditions could cause the
HS application to crash, resulting in a denial-of-service condition and
processor reset.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
NASA reports that an official fix is currently under development and is expected to be included in a future software release. As an interim mitigation, users can update their HS app from the HS repo ( https://github.com/nasa/HS ) to the latest dev branch. The fix is in the dev branch starting at commit 828855f971db4b6714367ed0a970f52dbeab2965
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a denial-of-service condition and processor reset. | |
| Title | NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-07-30T21:35:14.061Z
Reserved: 2026-07-28T14:10:13.503Z
Link: CVE-2026-18064
No data.
No data.
No data.
OpenCVE Enrichment
No data.