← Voltar à pesquisa de CVEs

CVE-2026-73523

Open1722

Descrição

COVESA Open1722 through 0.9.2 contains an integer truncation vulnerability in acf-can-listener.c that allows unauthenticated remote attackers to cause the CAN listener to transmit process stack memory onto the CAN bus by sending a rejected UDP datagram with a matching AVTP stream ID. The num_can_msgs variable declared as uint8_t truncates the -1 error return value from avtp_to_can() to 255, causing a write loop to iterate 255 times over a 15-slot stack array and leak approximately 18 KB of adjacent stack memory as roughly 240 CAN frames to any recipient on the CAN bus.

CVSS 7.5EPSS 0.32399999999999995%Risco 0.77
Ver fonte
Publicação
2026-08-17 18:18:14
Versões afetadas
<=0.9.2
Tipo
Biblioteca
Última alteração
2026-08-17 19:16:40
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N