CVE-2026-18582

Source
https://cve.org/CVERecord?id=CVE-2026-18582
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18582.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-18582
Aliases
  • GHSA-7qg8-hm25-rv5v
Published
2026-08-03T01:15:12.285Z
Modified
2026-08-07T20:13:15.158336Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
mz-automation libiec61850 Report Sending Path reporting.c Reporting_RCBWriteAccessHandler free of memory not on the heap
Details

A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function ReportingRCBWriteAccessHandler of the file src/iec61850/server/mmsmapping/reporting.c of the component Report Sending Path Handler. The manipulation results in free of memory not on the heap. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.2 is able to resolve this issue. The patch is identified as 5b2a69f44256b8548927d8afdd7ac5f5381abe1e. It is suggested to upgrade the affected component. The vendor was contacted early about this disclosure.

Database specific
{
    "cwe_ids": [
        "CWE-590"
    ],
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18582.json"
}
References

Affected packages

Git / github.com/mz-automation/libiec61850

Affected ranges

Type
GIT
Repo
https://github.com/mz-automation/libiec61850
Events
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "1.6.0"
        },
        {
            "last_affected": "1.6.0"
        },
        {
            "introduced": "1.6.1"
        },
        {
            "last_affected": "1.6.1"
        }
    ]
}

Affected versions

1.*
1.6.0
1.6.1
v1.*
v1.6.0
v1.6.1

Database specific

vanir_signatures
[
    {
        "digest": {
            "length": 10809.0,
            "function_hash": "239492926260023520981197973325102882426"
        },
        "deprecated": false,
        "source": "https://github.com/mz-automation/libiec61850/commit/5b2a69f44256b8548927d8afdd7ac5f5381abe1e",
        "signature_type": "Function",
        "target": {
            "file": "src/iec61850/server/mms_mapping/reporting.c",
            "function": "sendNextReportEntrySegment"
        },
        "signature_version": "v1",
        "id": "CVE-2026-18582-44026881"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "135553824467105894718493901937997193267",
                "133953580618150493851030447315505619404",
                "76166046935499232825858244244483143153",
                "255942837568997588166263166035279375383",
                "94027603216468330018588814376814986794",
                "153293100347285870660099630188449328859",
                "154426502658573711154635227123803054433",
                "204063307851803203941955467660122151749",
                "93163946215245591929493921064490970480",
                "161564712357783557356327442379769362177"
            ]
        },
        "deprecated": false,
        "source": "https://github.com/mz-automation/libiec61850/commit/5b2a69f44256b8548927d8afdd7ac5f5381abe1e",
        "signature_type": "Line",
        "target": {
            "file": "src/iec61850/server/mms_mapping/reporting.c"
        },
        "signature_version": "v1",
        "id": "CVE-2026-18582-89ba954f"
    },
    {
        "digest": {
            "length": 17357.0,
            "function_hash": "183400584457095388775570597020912256281"
        },
        "deprecated": false,
        "source": "https://github.com/mz-automation/libiec61850/commit/5b2a69f44256b8548927d8afdd7ac5f5381abe1e",
        "signature_type": "Function",
        "target": {
            "file": "src/iec61850/server/mms_mapping/reporting.c",
            "function": "Reporting_RCBWriteAccessHandler"
        },
        "signature_version": "v1",
        "id": "CVE-2026-18582-9506666a"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18582.json"
vanir_signatures_modified
"2026-08-07T20:13:15Z"