Description
S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificationList. Attackers can trigger heap allocation failures on sessions with both data-change and event notifications to cause the server process to terminate.
Published: 2026-09-13
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Update
AI Analysis

Impact

S2OPC through version 1.7.3 suffers a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items(); when an allocation for DataChangeNotification fails, a later successful allocation for EventNotificationList overwrites the null pointer. This causes the server process to crash, resulting in a denial of service. The weakness is a classic null pointer dereference mapped to CWE‑476.

Affected Systems

The affected product is Systerel S2OPC, all releases up to and including 1.7.3. The flaw impacts any instance of the toolkit that processes OPC UA sessions capable of both data‑change and event notifications, such as OPC UA servers or clients built on this toolkit.

Risk and Exploitability

The CVSS score of 6.0 indicates a moderate severity. The EPSS score is below 1% and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation is known. Attackers can trigger heap allocation failures through external OPC UA clients that initiate a subscription containing both data‑change and event notifications, leading to a server crash. The impact is confined to availability, with no remote code execution or privilege escalation.

Generated by OpenCVE AI on September 15, 2026 at 16:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade S2OPC to a newer version than 1.7.3 that addresses the allocation bug.
  • If an immediate upgrade is not possible, re‑configure or disable concurrent data‑change and event notifications within the same session to prevent simultaneous allocation attempts.
  • Deploy a watchdog or monitoring process that restarts the server promptly if it crashes and alerts administrators to abnormal termination events.

Generated by OpenCVE AI on September 15, 2026 at 16:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Systerel
Systerel s2opc
Vendors & Products Systerel
Systerel s2opc

Sun, 13 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificationList. Attackers can trigger heap allocation failures on sessions with both data-change and event notifications to cause the server process to terminate.
Title S2OPC through 1.7.3 NULL Pointer Dereference in alloc_notification_message_items()
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T17:26:08.686Z

Reserved: 2026-09-13T12:01:31.544Z

Link: CVE-2026-90782

cve-icon Vulnrichment

Updated: 2026-09-14T17:26:03.181Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T13:16:29.410

Modified: 2026-09-23T17:17:44.423

Link: CVE-2026-90782

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:00:14Z

Weaknesses