Junglewise Threat Intelligence

CVE-2026-56790: CANBoat off-by-one buffer overflow in searchForPgn

CVE-2026-56790 · Severity: high · CVSS 7.3 · Published 2026-06-25

Executive brief

CANBoat is a suite of tools used to decode NMEA-2000 marine data from boat networks. A vulnerability in how the software processes message headers allows an attacker to crash the application by sending a specially crafted message. This could lead to a loss of navigation data or monitoring capabilities on affected maritime systems.

Technical details

An off-by-one error (CWE-193) exists in the searchForPgn() function within analyzer/pgn.c. The binary search implementation used a closed range where the upper bound was set to the element count rather than the last index, and the loop condition used 'start <= end'. When processing an out-of-range Parameter Group Number (PGN) from an N2K message header, the search converges on an index equal to the array size, resulting in an out-of-bounds read of the global pgnList array. This can be triggered via CAN bus or N2K-over-IP, leading to an application crash (DoS). The issue is fixed in commit a5a22b7 by transitioning to a half-open range [start, end).

Affected products

  • canboat CANBoat through 6.22

Timeline

  • 2026-06-24: patched: Fix merged in commit a5a22b7
  • 2026-06-25: disclosed: CVE-2026-56790 published

References