What is CVE-2026-74238?
CVE-2026-74238 is an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function within TIER IV Nebula through version 1.2.0, allowing unauthenticated remote attackers to read past the end of a UDP buffer in heap memory by sending a short UDP datagram. The flaw can disrupt sensor data processing, potentially leading to denial of service (DoS). Users are advised to update the software promptly.
Azərbaycanca: CVE-2026-74238 TIER IV Nebula-nın 1.2.0 versiyasına qədər olan Vlp32Decoder::unpack() funksiyasında, autentifikasiya olunmamış uzaqdan hücumçuya qısa UDP datagramı göndərərək heap yaddaşını oxutdurmağa imkan verən out-of-bounds read zəifliyidir. Bu boşluq sensor məlumatlarının işlənməsini pozaraq potensial xidmət rəddinə (DoS) səbəb ola bilər. İstifadəçilərə dərhal proqram təminatını yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Which versions of TIER IV Nebula are affected by CVE-2026-74238?
This vulnerability affects all versions of TIER IV Nebula through version 1.2.0.
Does exploiting CVE-2026-74238 require authentication?
No, this vulnerability can be exploited by unauthenticated remote attackers.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.