High severity7.5NVD Advisory· Published Aug 17, 2026
CVE-2026-73522
CVE-2026-73522
Description
COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to write past the end of a fixed 15-slot stack array by sending a crafted UDP datagram containing more than 15 ACF-CAN messages. The avtp_to_can() function increments its write index without bounding it against the caller-supplied array size, and because the listener accepts datagrams from any sender matching a hardcoded unauthenticated stream ID transmitted in plaintext, attackers can corrupt adjacent stack memory to achieve arbitrary code execution or denial of service.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.