PT-2026-52544 · Libais · Libais
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
libais versions prior to 0.16
Description
The
VdmStream::AddLine() function uses an unchecked sentinel value as a vector index when processing AIS sentences that contain empty or out-of-range sequential message IDs. This leads to out-of-bounds memory access and potential corruption, allowing remote attackers to crash services or vessel systems by sending crafted AIVDM sentences via VHF marine radio or IP feeds.Recommendations
Update libais to version 0.16 or later.
Exploit
Fix
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libais