PT-2026-52553 · Canboat · Canboat

·

CVE-2026-56790

·

Published

2026-06-25

·

Updated

2026-06-26

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions CANBoat versions prior to 6.23
Description An off-by-one global buffer overflow exists in the searchForPgn() function within the analyzer/pgn.c file. A remote attacker can trigger an out-of-bounds array access and cause a denial of service, resulting in an application crash, by sending a crafted NMEA-2000 message containing an out-of-range PGN value via the CAN bus or N2K-over-IP.
Recommendations Update to the version containing commit a5a22b7.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56790

Affected Products

Canboat