Junglewise Threat Intelligence

CVE-2026-73523: COVESA Open1722 integer truncation stack memory disclosure in acf-can-listener

CVE-2026-73523 · Severity: high · CVSS 7.5 · Published 2026-08-17

Executive brief

COVESA Open1722 is an automotive networking library used to transport CAN bus messages over IP networks, critical for vehicle communication systems. A flaw in the CAN listener component allows remote attackers to leak sensitive stack memory by sending specially crafted network packets; the leaked memory is then broadcast to all devices on the CAN bus, potentially exposing configuration data, keys, or other sensitive information.

Technical details

The vulnerability is an integer truncation error (CWE-197) in acf-can-listener.c where the return value of avtp_to_can() (an int that can be -1 on error) is assigned to num_can_msgs, declared as uint8_t. When avtp_to_can() returns -1, it is truncated to 255, causing a subsequent write loop to iterate 255 times over a 15-slot stack array. This reads approximately 18 KB of adjacent stack memory and writes it as roughly 240 CAN frames onto the CAN bus. The attack requires only a matching AVTP stream ID (the default is hardcoded and sent in plaintext) and no authentication. While the vulnerable code is marked EXCLUDE_FROM_ALL in the examples directory, a similar pattern exists in the Zephyr RTOS variant where exposure is higher. The fix requires bounding the avtp_to_can() function with a capacity parameter and checking for negative return values before the write loop.

Affected products

  • COVESA Open1722 through 0.9.2

Timeline

  • 2026-08-17: disclosed
  • 2026-08-17: advisory: CVE-2026-73523 assigned

References

Related threats