What is CVE-2026-50103?
CVE-2026-50103 is a NULL pointer dereference vulnerability in the L2 GOOSE and R-GOOSE shared parser. It could allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE frame with a malformed TLV value. Affected systems should update the parser or apply network-level mitigations.
Azərbaycanca: CVE-2026-50103 zəifliyi L2 GOOSE və R-GOOSE paylaşılan parser-də NULL pointer dereference-dən qaynaqlanır. Bu, şəbəkəyə qonşu olan təcavüzkarın xüsusi hazırlanmış, səhv TLV dəyəri daşıyan GOOSE kadrı göndərərək abunə olan tətbiqi çökdürməsinə imkan verə bilər. Təsirə məruz qalan sistemlərdə parser yenilənməli və ya şəbəkə səviyyəsində qoruyucu tədbirlər tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-476
FAQ2
What conditions must an attacker meet to exploit CVE-2026-50103?
The attacker must be network-adjacent and send a crafted GOOSE frame with a malformed TLV value.
Which functional component contains CVE-2026-50103?
The vulnerability exists as a NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.