PT-2026-76755 · Covesa+1 · Open1722

·

CVE-2026-73523

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions COVESA Open1722 versions 0.1722 through 0.9.2
Description An integer truncation issue exists in acf-can-listener.c. Unauthenticated remote attackers can cause the CAN listener to transmit process stack memory onto the CAN bus by sending a rejected UDP datagram with a matching AVTP stream ID. The num can msgs variable, declared as uint8 t, truncates the -1 error return value from the avtp to can() function to 255. This causes a write loop to iterate 255 times over a 15-slot stack array, leaking approximately 18 KB of adjacent stack memory as roughly 240 CAN frames to any recipient on the CAN bus.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73523

Affected Products

Open1722