CVE-2026-38570 Details
Description
bacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode which allows attackers to cause a denial of service.
A denial-of-service vulnerability has been identified in BACnet Stack version 1.3.1. The issue arises from an out-of-bounds read in the function 'bacnet_tag_number_decode', which is part of the BACnet application layer decoding process. This vulnerability can be exploited by sending a malformed BACnet UCOV (Change of Value) notification that includes an oversized property-value payload. The decoding function fails to properly validate the length of the payload against the available data, leading to an invalid memory read that causes a segmentation fault and crashes the application.
Users are advised to update to the latest version of BACnet Stack, as this vulnerability has been addressed in the version 1.5.0 release.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 4, 2026CISA-ADP
Assessed Jun 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bacnet-stack/bacnet-stack | [email protected] | Vendor |
| https://github.com/bacnet-stack/bacnet-stack/issues/1270 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| bacnet-stack | 1.3.1 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 8, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | New CVE Received | [email protected] |
Volerion