What is CVE-2026-73522?
A critical stack buffer overflow vulnerability exists in COVESA Open1722 versions through 0.9.2. An unauthenticated remote attacker can write past the end of a fixed 15-slot stack array by sending a crafted UDP datagram containing more than 15 ACF-CAN messages via the avtp_to_can() function. Developers should validate the index increment and apply security patches immediately.
Azərbaycanca: COVESA Open1722 0.9.2-yə qədər versiyalarında kritik stack buffer overflow zəifliyi aşkar edilib. İdentifikasiyasız uzaqdan hücumçu xüsusi hazırlanmış UDP datagramı göndərərək 15 yuvalı stack massivinin hüdudlarından kənara yaza bilər. Tərtibatçılar avtp_to_can() funksiyasında indeks artımını yoxlamalı və təhlükəsizlik yamasını tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-119
FAQ1
How can an unauthenticated remote attacker exploit the CVE-2026-73522 vulnerability?
By sending a crafted UDP datagram containing more than 15 ACF-CAN messages via the avtp_to_can() function, the attacker can write past the end of the fixed 15-slot stack array.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.