Description
A memory buffer overflow vulnerability exists in the internal diagnostic and route validation routines used by the Fabric Shortest Path First (FSPF) protocol component of Brocade Fabric OS versions before 10.0.1. While this code path is part of internal diagnostic functionality and is not directly accessible via standard user interfaces or CLI management commands, an input processing flaw allows incoming or internally routed diagnostic state payloads to exceed allocated memory boundaries. An attacker that is able to chain or link other vulnerabilities to exploit this internal diagnostic could cause a heap- or stack-based memory overrun, resulting in a daemon crash (Denial of Service) or potential arbitrary code execution within the context of the routing daemon.
Published: 2026-10-08
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service and potential arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

A buffer overflow exists in the internal diagnostic and route validation routines of Brocade Fabric OS prior to 10.0.1. This flaw allows incoming or internally routed diagnostic state payloads to exceed allocated memory boundaries, which can lead to a heap- or stack-based memory overrun. When successfully exploited, the routing daemon can crash, resulting in a denial of service, or the attacker may achieve arbitrary code execution within the daemon’s context.

Affected Systems

Brocade Fabric OS versions below 10.0.1, specifically the Fabric Shortest Path First (FSPF) component. All installations of Fabric OS pre‑10.0.1 are vulnerable; the security update starting in 10.0.1 resolves the defect.

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity. Because the affected code path is not exposed via standard user interfaces, an attacker would need to chain this flaw with another weakness or gain internal diagnostic access to trigger the overflow. No KEV listing or known exploit campaigns exist, and EPSS is not available, suggesting exploitation likelihood is low for isolated systems. Nonetheless, the potential for denial of service or code execution warrants prompt mitigation.

Generated by OpenCVE AI on October 8, 2026 at 04:36 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 10.0.1


OpenCVE Recommended Actions

  • Apply the security update that ships with Brocade Fabric OS 10.0.1 or later.
  • If the update is not immediately deployable, isolate or disable internal diagnostic state payload handling to reduce the attack surface until a fix is available.
  • Monitor system logs for routing daemon crashes or abnormal diagnostic traffic, and treat any such anomalies as potential exploitation attempts.

Generated by OpenCVE AI on October 8, 2026 at 04:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 05:00:00 +0000

Type Values Removed Values Added
Title Fabric OS Internal Diagnostic State Payload Buffer Overflow Vulnerability
First Time appeared Brocade
Brocade fabric Os
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 03:15:00 +0000

Type Values Removed Values Added
Description A memory buffer overflow vulnerability exists in the internal diagnostic and route validation routines used by the Fabric Shortest Path First (FSPF) protocol component of Brocade Fabric OS versions before 10.0.1. While this code path is part of internal diagnostic functionality and is not directly accessible via standard user interfaces or CLI management commands, an input processing flaw allows incoming or internally routed diagnostic state payloads to exceed allocated memory boundaries. An attacker that is able to chain or link other vulnerabilities to exploit this internal diagnostic could cause a heap- or stack-based memory overrun, resulting in a daemon crash (Denial of Service) or potential arbitrary code execution within the context of the routing daemon.
Weaknesses CWE-120
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T03:03:01.051Z

Reserved: 2026-09-21T20:29:06.561Z

Link: CVE-2026-94582

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T03:16:37.980

Modified: 2026-10-08T03:16:37.980

Link: CVE-2026-94582

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T04:45:17Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')