What is CVE-2026-73523?
CVE-2026-73523 is an integer truncation vulnerability in `acf-can-listener.c` of COVESA Open1722 up to version 0.9.2. It allows unauthenticated remote attackers to transmit process stack memory onto the CAN bus by sending a rejected UDP datagram with a matching AVTP stream ID, potentially exposing sensitive data. Immediate patching and network access restrictions are strongly recommended.
Azərbaycanca: CVE-2026-73523, COVESA Open1722-nin 0.9.2 versiyasına qədər olan versiyalarında `acf-can-listener.c` faylında tam ədəd kəsilməsi zəifliyidir. Bu, autentifikasiya olunmamış uzaq hücumçulara rədd edilmiş xüsusi UDP datagramı göndərərək CAN avtobusuna proses yığını yaddaşını ötürməyə imkan verir. İstifadəçilər dərhal yamaqları tətbiq etməli və şəbəkə girişini məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-190
FAQ2
Which versions of COVESA Open1722 are affected by CVE-2026-73523?
This vulnerability affects COVESA Open1722 versions up to 0.9.2.
What can an attacker achieve by exploiting CVE-2026-73523?
An unauthenticated remote attacker can transmit process stack memory onto the CAN bus by sending a specially crafted, rejected UDP datagram with a matching AVTP stream ID.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.