Vulnerability Description
COVESA Open1722 through 0.9.2 contains an integer truncation vulnerability in acf-can-listener.c that allows unauthenticated remote attackers to cause the CAN listener to transmit process stack memory onto the CAN bus by sending a rejected UDP datagram with a matching AVTP stream ID. The num_can_msgs variable declared as uint8_t truncates the -1 error return value from avtp_to_can() to 255, causing a write loop to iterate 255 times over a 15-slot stack array and leak approximately 18 KB of adjacent stack memory as roughly 240 CAN frames to any recipient on the CAN bus.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/COVESA/Open1722/issues/154
- https://www.vulncheck.com/advisories/covesa-open1722-stack-memory-disclosure-via
FAQ
What is CVE-2026-73523?
CVE-2026-73523 is a vulnerability with a CVSS score of 7.5 (HIGH). COVESA Open1722 through 0.9.2 contains an integer truncation vulnerability in acf-can-listener.c that allows unauthenticated remote attackers to cause the CAN listener to transmit process stack memory...
How severe is CVE-2026-73523?
CVE-2026-73523 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-73523?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.