PatchSiren

COVESA CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH COVESA CVE published 2026-08-17

CVE-2026-73523

CVE-2026-73523 is an integer truncation vulnerability in COVESA Open1722 through 0.9.2 that allows unauthenticated remote attackers to cause the CAN listener to transmit process stack memory onto the CAN bus. This vulnerability has a high CVSS score of 8.7 and could potentially lead to stack memory disclosure. Defenders responsible for CAN bus systems, particularly those using COVESA Open1722, should asse [truncated]

HIGH COVESA CVE published 2026-08-17

CVE-2026-73522

CVE-2026-73522 is a stack buffer overflow vulnerability in COVESA Open1722 through version 0.9.2. The vulnerability allows unauthenticated remote attackers to write past the end of a fixed 15-slot stack array by sending a crafted UDP datagram containing more than 15 ACF-CAN messages. This can lead to arbitrary code execution or denial of service. The vulnerability is caused by the avtp_to_can() function i [truncated]