{"id":"CVE-2026-19108","summary":"MZ Automation libiec61850 URCB Revalidation reporting.c deleteDataSetValuesShadowBuffer use after free","details":"A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetValuesShadowBuffer of the file src/iec61850/server/mms_mapping/reporting.c of the component URCB Revalidation. The manipulation results in use after free. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 1.6.2 is sufficient to fix this issue. The patch is identified as 486fd57f3aed65bb9d636ff00f9ddce2e450b168. Upgrading the affected component is advised.","modified":"2026-08-14T09:05:48.787585Z","published":"2026-08-06T20:30:14.200Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-416"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19108.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19108.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19108"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-19108"},{"type":"ADVISORY","url":"https://vuldb.com/submit/864520"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/386569"},{"type":"REPORT","url":"https://github.com/mz-automation/libiec61850/issues/596"},{"type":"REPORT","url":"https://vuldb.com/vuln/386569/cti"},{"type":"FIX","url":"https://github.com/mz-automation/libiec61850/commit/486fd57f3aed65bb9d636ff00f9ddce2e450b168"},{"type":"FIX","url":"https://github.com/mz-automation/libiec61850/releases/tag/v1.6.2"},{"type":"EVIDENCE","url":"https://github.com/user-attachments/files/29163236/POC.zip"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mz-automation/libiec61850","events":[{"introduced":"519b0208cc79d1af09d5ca40fb9ad1fd93822e93"},{"fixed":"486fd57f3aed65bb9d636ff00f9ddce2e450b168"},{"fixed":"f0f797bf955da763353f7081c892a1ff6b55e5a1"}],"database_specific":{"extracted_events":[{"introduced":"1.6.0"},{"last_affected":"1.6.0"},{"introduced":"1.6.1"},{"last_affected":"1.6.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["1.6.0","1.6.1","v1.6.1","v1.6.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19108.json","vanir_signatures_modified":"2026-08-14T09:05:48Z","vanir_signatures":[{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["173377563981138650223645845979794833769","304599315377520186813690999442799150066","75707732626746220403782273183248073538","233693197047779142016951525167729288215"]},"id":"CVE-2026-19108-03fcf41a","signature_type":"Line","signature_version":"v1","source":"https://github.com/mz-automation/libiec61850/commit/486fd57f3aed65bb9d636ff00f9ddce2e450b168","target":{"file":"src/mms/iso_mms/server/mms_server_connection.c"}},{"deprecated":false,"digest":{"function_hash":"97242920355599622300547441929788907131","length":168},"id":"CVE-2026-19108-2f5e0f42","signature_type":"Function","signature_version":"v1","source":"https://github.com/mz-automation/libiec61850/commit/486fd57f3aed65bb9d636ff00f9ddce2e450b168","target":{"file":"src/iec61850/server/mms_mapping/mms_mapping.c","function":"MmsMapping_freeDynamicallyCreatedDataSet"}},{"signature_version":"v1","source":"https://github.com/mz-automation/libiec61850/commit/486fd57f3aed65bb9d636ff00f9ddce2e450b168","target":{"file":"src/iec61850/inc_private/reporting.h"},"deprecated":false,"digest":{"line_hashes":["307316742964203674681230520561418345422","232133855481966980230161678996677288889","294180839684934248797117833295273899723","88893192852150386699356094167793369649"],"threshold":0.9},"id":"CVE-2026-19108-2f847a54","signature_type":"Line"},{"target":{"file":"src/iec61850/server/mms_mapping/reporting.c"},"deprecated":false,"digest":{"line_hashes":["229651934041124409174423383899033824064","191194205021956966332356845487013805517","288904012295766299565140228973874683255","146184391766072490552115498273787593027","60102130869661658747589562464842372222","107118010369759597682734048466370909078","315143653522997655002760179268815512621","247993456202355196681841378316769711956","317062867232212139594423050684798406937","297182487279396042895099413657559250510","320936204763154971757289868901632070926","125385772231226582028399463856237883991","98424500944620728063889790948876151563","105732790516406710065700909172843513489"],"threshold":0.9},"id":"CVE-2026-19108-6384460b","signature_type":"Line","signature_version":"v1","source":"https://github.com/mz-automation/libiec61850/commit/486fd57f3aed65bb9d636ff00f9ddce2e450b168"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/mz-automation/libiec61850/commit/486fd57f3aed65bb9d636ff00f9ddce2e450b168","target":{"file":"src/iec61850/server/mms_mapping/mms_mapping.c"},"deprecated":false,"digest":{"line_hashes":["205540904867348212064742690756463449283","305655533337636333478768926530561721972","171702901039129279133230557083636986823","38875661548947508435583131304420011830","287846922922393015834898580431728254963","693314570242981976707863391375747324","155084251910005058403792063008938341753","95544962612544120750303520503677128839","227079288826847374461184722053374085337","36750559283255173388989797570010463148","155084251910005058403792063008938341753","227079288826847374461184722053374085337","36750559283255173388989797570010463148","155084251910005058403792063008938341753","83550446663225275594924474307194102283","75407180318704451699303769443305508093","108587633537507210242609878158511307392","108587633537507210242609878158511307392","108587633537507210242609878158511307392","156887579857374435510064138335644398771","29989680149395580764487444276581547437","246642607780837746117598949341481121868","223761186038872770795196210062269025568","312254074297417132950046790845480392546","332390593246968337491883065469630484848"],"threshold":0.9},"id":"CVE-2026-19108-79c4d4ca"},{"source":"https://github.com/mz-automation/libiec61850/commit/486fd57f3aed65bb9d636ff00f9ddce2e450b168","target":{"file":"src/iec61850/server/mms_mapping/reporting.c","function":"deleteDataSetValuesShadowBuffer"},"deprecated":false,"digest":{"function_hash":"256350509602537573757781043097157032452","length":504},"id":"CVE-2026-19108-7d585d2c","signature_type":"Function","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/mz-automation/libiec61850/commit/486fd57f3aed65bb9d636ff00f9ddce2e450b168","target":{"function":"variableListAccessHandler","file":"src/iec61850/server/mms_mapping/mms_mapping.c"},"deprecated":false,"digest":{"length":4041,"function_hash":"248476144158460735190721448100521283305"},"id":"CVE-2026-19108-a231ba54","signature_type":"Function"},{"deprecated":false,"digest":{"function_hash":"44319375609194462658837977497421968958","length":472},"id":"CVE-2026-19108-a9877e6f","signature_type":"Function","signature_version":"v1","source":"https://github.com/mz-automation/libiec61850/commit/486fd57f3aed65bb9d636ff00f9ddce2e450b168","target":{"file":"src/iec61850/server/mms_mapping/reporting.c","function":"createDataSetValuesShadowBuffer"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/mz-automation/libiec61850/commit/486fd57f3aed65bb9d636ff00f9ddce2e450b168","target":{"function":"MmsServerConnection_destroy","file":"src/mms/iso_mms/server/mms_server_connection.c"},"deprecated":false,"digest":{"length":441,"function_hash":"248929936866285992054979343424147344695"},"id":"CVE-2026-19108-b766f14c"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}