Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 13 Sep 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Systerel
Systerel s2opc |
|
| Vendors & Products |
Systerel
Systerel s2opc |
Sun, 13 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificationList. Attackers can trigger heap allocation failures on sessions with both data-change and event notifications to cause the server process to terminate. | |
| Title | S2OPC through 1.7.3 NULL Pointer Dereference in alloc_notification_message_items() | |
| Weaknesses | CWE-476 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T17:26:08.686Z
Reserved: 2026-09-13T12:01:31.544Z
Link: CVE-2026-90782
Updated: 2026-09-14T17:26:03.181Z
Status : Received
Published: 2026-09-13T13:16:29.410
Modified: 2026-09-14T18:20:26.747
Link: CVE-2026-90782
No data.
OpenCVE Enrichment
Updated: 2026-09-15T17:00:14Z