Vulnerability Description
MOOS-IvP through 24.8.1 contains a denial of service vulnerability in the Demuxer::addMuxPacket() function that trusts the packet count declared in mux headers without validation. Attackers can declare arbitrarily large packet counts to trigger unbounded memory allocation, exhausting system resources and causing service unavailability.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/moos-ivp/moos-ivp
- https://github.com/moos-ivp/moos-ivp/blob/1de9ae146cd63c209e8c3fd81611a4ed247297
- https://github.com/moos-ivp/moos-ivp/commit/fc5649ac12915f66a9f09520cdb6b14bc6d7
- https://github.com/moos-ivp/moos-ivp/pull/129
- https://www.vulncheck.com/advisories/moos-ivp-through-24.8.1-bhv-ipf-demultiplex
FAQ
What is CVE-2026-85445?
CVE-2026-85445 is a vulnerability with a CVSS score of 7.5 (HIGH). MOOS-IvP through 24.8.1 contains a denial of service vulnerability in the Demuxer::addMuxPacket() function that trusts the packet count declared in mux headers without validation. Attackers can declar...
How severe is CVE-2026-85445?
CVE-2026-85445 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-85445?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.