CVE-2026-73523 is an integer truncation vulnerability in COVESA Open1722 through 0.9.2 that allows unauthenticated remote attackers to cause the CAN listener to transmit process stack memory onto the CAN bus. This vulnerability has a high CVSS score of 8.7 and could potentially lead to stack memory disclosure. Defenders responsible for CAN bus systems, particularly those using COVESA Open1722, should asse [truncated]
CVE-2026-73522 is a stack buffer overflow vulnerability in COVESA Open1722 through version 0.9.2. The vulnerability allows unauthenticated remote attackers to write past the end of a fixed 15-slot stack array by sending a crafted UDP datagram containing more than 15 ACF-CAN messages. This can lead to arbitrary code execution or denial of service. The vulnerability is caused by the avtp_to_can() function i [truncated]