PT-2026-36508 · Undefined · Undefined

Feng Ning

·

Published

2026-05-01

·

Updated

2026-05-12

·

CVE-2026-37534

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open-SAE-J1939 versions prior to commit b6caf884df46435e539b1ecbf92b6c29b345bdfe
Description An integer underflow exists in the SAE J1939 Read Transport Protocol Data Transfer() function. This allows attackers to write to arbitrary memory by using a crafted sequence number from the CAN frame.
Recommendations Update to a version containing commit b6caf884df46435e539b1ecbf92b6c29b345bdfe.

Fix

Integer Underflow

Weakness Enumeration

Related Identifiers

CVE-2026-37534

Affected Products

Undefined