Executive brief
A vulnerability exists in the low-level CAN bus service of Automotive Grade Linux, a platform used in vehicle infotainment and instrument clusters. This flaw allows an attacker to send specially crafted diagnostic requests that can crash the service or potentially take control of the underlying system. Such an exploit could disrupt vehicle operations or compromise the security of the automotive electronic control units (ECUs).
Technical details
A stack-based buffer overflow exists in the uds-c library used by agl-service-can-low-level through version 17.1.12. The 'send_diagnostic_request' function in 'uds.c' allocates a 6-byte stack buffer but performs a memcpy of up to 7 bytes based on the 'payload_length' field without performing bounds checking. This results in a controlled stack overflow of 1-4 bytes. On 32-bit ARM automotive ECUs lacking stack canaries, this vulnerability can be exploited to overwrite the return address and achieve remote code execution (RCE). The issue is reachable over the network via the CAN service API.
Affected products
- Automotive Grade Linux agl-service-can-low-level up to and including 17.1.12
Timeline
- 2026-04-30: disclosed: Initial disclosure by Innora Security Research
- 2026-05-01: advisory: CVE-2026-37530 published