Impact
A logic flaw in the exploration state machine of the RACER project causes the application to enter an invalid or infinite processing loop, resulting in a crash or unresponsive behavior. The problematic state transition handling can be triggered by specially crafted inputs, directly compromising the availability of the system.
Affected Systems
The vulnerability affects the RACER codebase maintained by the SYSU STAR Group. The affected code is identified by commit abcdef1234567890; no other vendor or product versions are enumerated as impacted.
Risk and Exploitability
The CVSS score of 7.5 and an EPSS score of less than 1% indicate a moderate severity but low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an attacker sending malicious control inputs to the RACER state machine, which, if accepted, will trigger the denial of service. The flaw exists in application logic and does not require privileged access, but an adversary must be able to influence state transitions.
OpenCVE Enrichment