CVE-2026-90782
Severity CVSS v4.0:
MEDIUM
Type:
CWE-476
NULL Pointer Dereference
Publication date:
13/09/2026
Last modified:
23/09/2026
Description
S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificationList. Attackers can trigger heap allocation failures on sessions with both data-change and event notifications to cause the server process to terminate.
Impact
Base Score 4.0
6.00
Severity 4.0
MEDIUM
Base Score 3.x
5.30
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://gitlab.com/systerel/S2OPC
- https://gitlab.com/systerel/S2OPC/-/blob/S2OPC_Toolkit_1.7.3/src/ClientServer/services/b2c/msg_subscription_publish_bs.c#L106-L147
- https://gitlab.com/systerel/S2OPC/-/commit/8848f051eed069b107ae7cb16a346d6f6386a8f5
- https://gitlab.com/systerel/S2OPC/-/issues/1815
- https://gitlab.com/systerel/S2OPC/-/merge_requests/1862
- https://www.vulncheck.com/advisories/s2opc-through-1.7.3-null-pointer-dereference-in-alloc-notification-message-items
- https://gitlab.com/systerel/S2OPC/-/issues/1815


