Junglewise Threat Intelligence

CVE-2026-54413: driftregion iso14229 integer underflow in Handle_0x27_SecurityAccess

CVE-2026-54413 · Severity: high · CVSS 8.2 · Published 2026-06-14

Executive brief

A vulnerability exists in a popular software library used for automotive and industrial communications (UDS protocol). An unauthenticated attacker can send a specially crafted message to a device using this library to cause it to crash or potentially leak sensitive internal memory. This affects critical systems like vehicle engine control units (ECUs), industrial controllers, and IoT devices, potentially disrupting operations or exposing technical data.

Technical details

An integer underflow vulnerability exists in the Handle_0x27_SecurityAccess() function within iso14229.c. The handler fails to validate that the received message length (recv_len) is at least 2 bytes before indexing into the buffer and performing an unsigned subtraction: (uint16_t)(recv_len - UDS_0X27_REQ_BASE_LEN). When a single-byte 0x27 request is received following a valid message, the calculation underflows to 65535. This large value is passed to application callbacks (SecAccessValidateKey or SecAccessRequestSeed), leading to an out-of-bounds read as the application attempts to process more data than the 4-KB receive buffer contains. This can result in a Denial of Service (crash) or information disclosure. The flaw is reachable over CAN, OBD-II, ISO-TP, and DoIP transports without authentication.

Affected products

  • driftregion iso14229 through 0.9.0

Timeline

  • 2026-06-14: advisory: CVE-2026-54413 published by NVD

References