PT-2026-76755 · Covesa+1 · Open1722
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
COVESA Open1722 versions 0.1722 through 0.9.2
Description
An integer truncation issue exists in acf-can-listener.c. Unauthenticated remote attackers can cause the CAN listener to transmit process stack memory onto the CAN bus by sending a rejected UDP datagram with a matching AVTP stream ID. The
num can msgs variable, declared as uint8 t, truncates the -1 error return value from the avtp to can() function to 255. This causes a write loop to iterate 255 times over a 15-slot stack array, leaking approximately 18 KB of adjacent stack memory as roughly 240 CAN frames to any recipient on the CAN bus.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open1722