CVE-2026-67976 Details
Description
The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via inputting unsafe parameters.
A denial-of-service vulnerability has been identified in the Ref::SignalGen component of the Fprime framework, specifically in version 4.2.2. The issue arises because the component does not properly validate user-controlled parameters, allowing attackers to input unsafe values that lead to a crash. When the component is in the 'running' state', it processes these unsafe inputs in a way that triggers a modulo-by-zero error, causing a floating-point exception and terminating the process.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 3, 2026CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/freedomfoxvare/cve/issues/2 | CISA-ADP | ExploitTechnical Analysis |
| https://github.com/freedomfoxvare/cve/issues/2 | [email protected] | ExploitTechnical Analysis |
| https://github.com/nasa/fprime | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| nasa/fprime | v4.2.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | New CVE Received | [email protected] |
Volerion