Out-of-bounds read in libIEC61850 - #VU136969
Published: July 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in the SV subscriber getter functions when processing a malformed Sampled Values frame with a fixed-width field encoded with an invalid shorter length. A remote attacker can send a specially crafted SV frame to cause a denial of service.
The issue is reachable from the normal subscriber callback path and can be triggered on the same Layer-2 network segment as the subscriber.