---
cve: "CVE-2026-90782"
severity: "MEDIUM"
cvss: 6.0
epss: "32%"
vendor: "Systerel"
kev: false
exploited: false
published: "2026-09-13 13:16:29"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-18T20:32:49+02:00"
---

# CVE-2026-90782

> 6.0 MEDIUM

## Beschreibung

S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificationList. Attackers can trigger heap allocation failures on sessions with both data-change and event notifications to cause the server process to terminate.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- 8848f051eed069b107ae7cb16a346d6f6386a8f5 (Commit)

## Referenzen

- <https://gitlab.com/systerel/S2OPC/-/issues/1815>
- <https://gitlab.com/systerel/S2OPC/-/commit/8848f051eed069b107ae7cb16a346d6f6386a8f5>
- <https://gitlab.com/systerel/S2OPC/-/blob/S2OPC_Toolkit_1.7.3/src/ClientServer/services/b2c/msg_subscription_publish_bs.c#L106-L147>
- <https://gitlab.com/systerel/S2OPC>
- <https://gitlab.com/systerel/S2OPC/-/merge_requests/1862>
- <https://www.vulncheck.com/advisories/s2opc-through-1.7.3-null-pointer-dereference-in-alloc-notification-message-items>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-90782) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
