PT-2026-85287 · Moos Ivp · Moos-Ivp

·

CVE-2026-85438

·

Published

2026-09-03

·

Updated

2026-09-04

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MOOS-IvP versions prior to 24.8.2
Description A buffer overflow exists in the StringToIvPFunction() function. The issue occurs when dimension, piece, and degree counts from encoded BHV IPF payloads are used as allocation sizes and loop bounds without proper validation. An attacker can provide crafted payloads with mismatched dimension values to write controlled doubles beyond the end of the IvPBox weight array, leading to memory corruption and potential code execution.
Recommendations Update MOOS-IvP to version 24.8.2 or later.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85438

Affected Products

Moos-Ivp