Critical NULL Pointer Dereference (CVE‑2026‑18064) in NASA cFS Health & Safety (HS) Application Enables DoS and Processor Reset
What It Is — The NASA Core Flight System (cFS) Health & Safety (HS) application (≤ v7.0.1) contains an incomplete fix for CVE‑2026‑15352 that leaves a separate NULL‑pointer dereference reachable. Triggering the vulnerable command can crash the HS process, causing a denial‑of‑service condition and a full processor reset.
Exploitability — CVSS v3 7.5 (High). No public exploit code is known, but the vulnerability is exploitable by an attacker who can issue the specific command under the required conditions (e.g., via a compromised ground‑station link).
Affected Products — NASA Core Flight System (cFS) Health & Safety (HS) Application, versions ≤ 7.0.1.
Why It Matters for Compliance & Audit Readiness
- Control Mapping: The flaw maps to SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management); evidence of remediation must be captured to demonstrate control effectiveness.
- Continuous Evidence: Enterprises that rely on cFS for mission‑critical transport systems need auditable proof that vulnerable firmware is patched or mitigated, otherwise they risk non‑compliance findings during a SOC 2 audit.
- Due Diligence: Documenting the vulnerability, the temporary mitigation, and the timeline for the official NASA fix satisfies vendor‑risk and supply‑chain due‑diligence requirements increasingly demanded by regulators and customers.
Recommended Actions
- Apply the NASA patch as soon as it is released; track patch status in your configuration‑management database (CMDB).
- Temporarily disable the vulnerable command or restrict its execution to authenticated, least‑privilege accounts.
- Map the issue to SOC 2 CC6.1/CC7.1, capture remediation evidence (patch tickets, configuration changes) in a tamper‑evident repository.
- Update incident‑response playbooks to include detection of the specific command failure and escalation procedures.
- Monitor for any anomalous command traffic from ground‑station interfaces.
Source: CISA Advisory – ICSA‑26‑211‑06