PT-2026-76756 · Tier Iv · Nebula
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TIER IV Nebula versions prior to 1.2.1
Description
An out-of-bounds read exists in the
Vlp32Decoder::unpack() function. This allows unauthenticated remote attackers to cause the decoder to read past the end of a received UDP buffer into adjacent heap memory by sending a short UDP datagram. By sending a malformed datagram to the Velodyne UDP sensor port, which lacks the sender-address restrictions found in other drivers, attackers can cause fabricated points derived from heap memory contents to be silently published into downstream PointCloud2 messages consumed by Autoware nodes.Recommendations
Update TIER IV Nebula to a version newer than 1.2.0.
As a temporary workaround, restrict access to the Velodyne UDP sensor port to minimize the risk of exploitation.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nebula