What is CVE-2026-67873?
CVE-2026-67873 is a heap-based buffer overflow vulnerability in the server-side FileSegment ASDU encoding path of lib60870-C 2.4.0. It occurs because FileSegment_encode() checks only the standalone segment length via FileSegment_GetMaxDataSize() without verifying the residual capacity of the current ASDU frame buffer. Affected systems should apply the necessary security patch.
Azərbaycanca: CVE-2026-67873, lib60870-C 2.4.0 kitabxanasının server tərəfində FileSegment ASDU kodlaşdırılması zamanı heap-based buffer overflow zəifliyidir. Problem, `FileSegment_encode()` funksiyasının yalnız fərdi seqment uzunluğunu yoxlayıb, ASDU çərçivəsindəki qalıq tutumu nəzərə almaması səbəbindən baş verir. Təsirə məruz qalan versiyadan istifadə edən sistemlərdə təhlükəsizlik yaması tətbiq olunmalıdır.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
Why does the CVE-2026-67873 vulnerability occur in the lib60870-C library?
The vulnerability occurs because the `FileSegment_encode()` function checks only the standalone segment length via `FileSegment_GetMaxDataSize()` without verifying the residual capacity of the current ASDU frame buffer.
What type of vulnerability is CVE-2026-67873 and which version of lib60870-C is affected?
It is a heap-based buffer overflow vulnerability that occurs in the server-side FileSegment ASDU encoding path of lib60870-C version 2.4.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.