COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to write past the end of a fixed 15-slot stack array by sending a crafted UDP datagram containing more than 15 ACF-CAN messages. The avtp_to_can() function increments its write index without bounding it against the caller-supplied array size, and because the listener accepts datagrams from any sender matching a hardcoded unauthenticated stream ID transmitted in plaintext, attackers can corrupt adjacent stack memory to achieve arbitrary code execution or denial of service.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-17 18:18
Updated : 2026-08-18 15:17
NVD link : CVE-2026-73522
Mitre link : CVE-2026-73522
CVE.ORG link : CVE-2026-73522
JSON object : View
Products Affected
No product.
CWE
CWE-121
Stack-based Buffer Overflow
