CVE-2026-67873
A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegmentencode() validates only the standalone segment length via FileSegmentGetMaxDataSize() and does not verify the residual capacity of the current ASDU frame before encoding object fields and segment data
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/mz-automation/lib60870/blob/master/user_guide.adoc, https://github.com/mz-automation/lib60870/releases/tag/v2.4.0, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67873.json, https://nvd.nist.gov/vuln/detail/CVE-2026-67873, https://github.com/mz-automation/lib60870/issues/201, https://github.com/mz-automation/lib60870